01Initial access
The victim runs a malicious attachment, installer, cracked application or other payload delivered through social engineering or a compromised channel.
en
Explore documented info-stealer families, variants and observed log or panel formats — and the behaviors defenders can investigate.
How the threat works
An information stealer is malware designed to collect valuable data from an infected device. Depending on the family, that can include browser credentials, session cookies, autofill data, cryptocurrency wallet material, files and device metadata. The collected data is usually packaged and sent to an operator for account takeover, fraud or resale.
01The victim runs a malicious attachment, installer, cracked application or other payload delivered through social engineering or a compromised channel.
02The malware enumerates supported applications, extracts selected data and prepares a structured package for exfiltration.
03Operators receive the stolen records and may use or sell them. A historical observation does not prove that a credential is still valid today.
Curated research snapshot
Select a row to load its curated public profile, including structured target and ATT&CK mappings.
188 entries in this catalog
This catalog covers entries CyStack analysts have tracked or documented while processing leak datasets and conducting threat-intelligence research. Entries may represent a family, variant, bundle, notice, stub or observed log or panel format; this does not imply that CyStack originally discovered every threat represented.
| Entry | Typical targets | ATT&CK | Related labels |
|---|---|---|---|
Typical targets0 | ATT&CK5 | Related labels2 | |
Typical targets4 | ATT&CK7 | Related labels1 | |
Typical targets3 | ATT&CK5 | Related labels6 | |
Typical targets5 | ATT&CK5 | Related labels0 | |
Typical targets1 | ATT&CK2 | Related labels3 | |
Typical targets4 | ATT&CK4 | Related labels2 | |
Typical targets5 | ATT&CK4 | Related labels4 | |
Typical targets4 | ATT&CK4 | Related labels1 | |
Typical targets10 | ATT&CK5 | Related labels2 | |
Typical targets10 | ATT&CK3 | Related labels6 | |
Typical targets6 | ATT&CK3 | Related labels5 | |
Typical targets5 | ATT&CK3 | Related labels3 | |
Typical targets4 | ATT&CK5 | Related labels1 | |
Typical targets0 | ATT&CK5 | Related labels3 | |
Typical targets3 | ATT&CK6 | Related labels1 | |
Typical targets4 | ATT&CK3 | Related labels2 | |
Typical targets4 | ATT&CK1 | Related labels1 | |
Typical targets0 | ATT&CK5 | Related labels2 | |
Typical targets1 | ATT&CK1 | Related labels4 | |
Typical targets4 | ATT&CK4 | Related labels1 | |
Typical targets8 | ATT&CK5 | Related labels4 | |
Typical targets3 | ATT&CK5 | Related labels2 | |
Typical targets4 | ATT&CK3 | Related labels0 | |
Typical targets3 | ATT&CK2 | Related labels0 |
This is a curated, non-exhaustive research snapshot — not a live inventory of every active campaign. A CyStack-coined parser or entry label is not definitive malware-family attribution; entries may cover variants, bundles, notices, stubs or observed log and panel formats. Techniques change over time, and the absence of an entry is not evidence that a threat does not exist. Validate important decisions with current security observations and qualified analysis.
Turn intelligence into action
CyStack Intel helps security teams investigate leaked credentials and infostealer observations associated with their organization.