01Initial access
The victim runs a malicious attachment, installer, cracked application or other payload delivered through social engineering or a compromised channel.
en
Explore documented info-stealer families, variants and observed log or panel formats — and the behaviors defenders can investigate.
How the threat works
An information stealer is malware designed to collect valuable data from an infected device. Depending on the family, that can include browser credentials, session cookies, autofill data, cryptocurrency wallet material, files and device metadata. The collected data is usually packaged and sent to an operator for account takeover, fraud or resale.
01The victim runs a malicious attachment, installer, cracked application or other payload delivered through social engineering or a compromised channel.
02The malware enumerates supported applications, extracts selected data and prepares a structured package for exfiltration.
03Operators receive the stolen records and may use or sell them. A historical observation does not prove that a credential is still valid today.
Curated research snapshot
Select a row to load its curated public profile, including structured target and ATT&CK mappings.
188 entries in this catalog
This catalog covers entries CyStack analysts have tracked or documented while processing leak datasets and conducting threat-intelligence research. Entries may represent a family, variant, bundle, notice, stub or observed log or panel format; this does not imply that CyStack originally discovered every threat represented.
| Entry | Typical targets | ATT&CK | Related labels |
|---|---|---|---|
Typical targets2 | ATT&CK2 | Related labels3 | |
Typical targets2 | ATT&CK3 | Related labels3 | |
Typical targets5 | ATT&CK5 | Related labels4 | |
Typical targets2 | ATT&CK3 | Related labels3 | |
Typical targets4 | ATT&CK4 | Related labels1 | |
Typical targets3 | ATT&CK4 | Related labels0 | |
Typical targets5 | ATT&CK5 | Related labels0 | |
Typical targets6 | ATT&CK9 | Related labels0 | |
Typical targets0 | ATT&CK3 | Related labels0 | |
Typical targets6 | ATT&CK6 | Related labels0 | |
Typical targets5 | ATT&CK6 | Related labels5 | |
Typical targets5 | ATT&CK5 | Related labels0 | |
Typical targets7 | ATT&CK7 | Related labels1 | |
Typical targets7 | ATT&CK6 | Related labels1 | |
Typical targets11 | ATT&CK9 | Related labels3 | |
Typical targets5 | ATT&CK5 | Related labels2 | |
Typical targets0 | ATT&CK3 | Related labels0 | |
Typical targets6 | ATT&CK6 | Related labels2 | |
Typical targets4 | ATT&CK4 | Related labels0 | |
Typical targets6 | ATT&CK8 | Related labels4 | |
Typical targets0 | ATT&CK2 | Related labels0 | |
Typical targets8 | ATT&CK8 | Related labels1 | |
Typical targets6 | ATT&CK10 | Related labels2 | |
Typical targets7 | ATT&CK7 | Related labels2 |
This is a curated, non-exhaustive research snapshot — not a live inventory of every active campaign. A CyStack-coined parser or entry label is not definitive malware-family attribution; entries may cover variants, bundles, notices, stubs or observed log and panel formats. Techniques change over time, and the absence of an entry is not evidence that a threat does not exist. Validate important decisions with current security observations and qualified analysis.
Turn intelligence into action
CyStack Intel helps security teams investigate leaked credentials and infostealer observations associated with their organization.