01Initial access
The victim runs a malicious attachment, installer, cracked application or other payload delivered through social engineering or a compromised channel.
en


A consolidated view of active Infostealers, variants, log and panel formats, and traceable indicators for security teams at organizations worldwide
Temporarily unavailable
How the threat works
An information stealer is malware designed to collect valuable data from an infected device. Depending on the family, that can include browser credentials, session cookies, autofill data, cryptocurrency wallet material, files and device metadata. The collected data is usually packaged and sent to an operator for account takeover, fraud or resale.
01The victim runs a malicious attachment, installer, cracked application or other payload delivered through social engineering or a compromised channel.
02The malware enumerates supported applications, extracts selected data and prepares a structured package for exfiltration.
Curated research snapshot
Select a row to load its curated public profile, including structured target and ATT&CK mappings.
Temporarily unavailable
This catalog covers entries CyStack analysts have tracked or documented while processing leak datasets and conducting threat-intelligence research. Entries may represent a family, variant, bundle, notice, stub or observed log or panel format; this does not imply that CyStack originally discovered every threat represented.
CyStack Intel could not return a catalog snapshot. Please try again later; the page will not substitute unreviewed data.
This is a curated, non-exhaustive research snapshot — not a live inventory of every active campaign. A CyStack-coined parser or entry label is not definitive malware-family attribution; entries may cover variants, bundles, notices, stubs or observed log and panel formats. Techniques change over time, and the absence of an entry is not evidence that a threat does not exist. Validate important decisions with current security observations and qualified analysis.
Defender's guide
Info stealers are built to turn data on an infected endpoint into reusable access. The exact collection scope varies by family and version, but defenders commonly investigate browser data, application secrets, financial assets and device context.
Saved usernames, passwords, autofill records, cookies and active session material can expose personal and business accounts. A stolen session may remain useful even after a password-only control is changed.
Depending on its capabilities, a stealer may seek cryptocurrency wallet material, messaging or gaming tokens, VPN and FTP credentials, selected files, screenshots or clipboard data.
An infection on a personal or unmanaged device can still expose corporate email, cloud sessions and remote-access credentials, creating an account-takeover and follow-on intrusion risk.
Treat the exposed endpoint and every associated account as an investigation scope, not just a password-reset task. Isolate and examine the device, revoke active sessions, reset credentials from a known-clean system, rotate exposed tokens or keys, review authentication activity and monitor for follow-on access. Historical leak data is an investigative lead; validate current impact with endpoint and identity telemetry.
Turn intelligence into action
CyStack Intel helps security teams investigate leaked credentials and infostealer observations associated with their organization.
03Operators receive the stolen records and may use or sell them. A historical observation does not prove that a credential is still valid today.