Chapter 2
How infostealers actually work
Understanding how these tools operate explains why traditional defences so often miss them — they are built to evade detection while maximising stolen value.
Infection
Malicious download, phishing link, or trojanised software — often shockingly mundane: a cracked app on a home machine that also touches corporate VPN.
Harvesting
Stealers comb browser stores (Chrome, Firefox, Edge), autofill, wallets, VPN configs, SSO tokens, and internal app credentials — methodically and quietly.
Exfiltration
Data is compressed, encrypted, and sent to attacker-controlled infrastructure. Operators often appear fileless, signed, or injected into legitimate processes.
Monetisation
Credentials are sold downstream to gangs and brokers — fuelling ransomware, fraud, and espionage at industrial scale.
The most dangerous piece is often the session cookie. Unlike passwords, valid session tokens can be replayed without MFA — pass-the-cookie is now standard in the ransomware playbook.