Malware
Infostealer
Also called stealer.
Infostealer is malware built to collect secrets: saved browser passwords, session cookies, crypto wallets, and files, then upload them to the attacker. It runs briefly and often removes itself.
How it is measured
Signs include a new process reading browser profile folders such as `Login Data` and `Cookies`, a burst of file access in the user's home directory, and a quick upload to an external host. EDR flags access to credential stores by an unfamiliar program.
After the fact, the sign is account misuse: a login from a new country, a session used without a password, or a wallet emptied.
Worked example
A freelance developer downloads a cracked design tool and runs it. For about 20 seconds a process reads Chrome's `Login Data`, Firefox's `cookies.sqlite`, and a folder of `.env` files, then posts a 3 MB archive to a Telegram bot. The program then exits.
Two days later someone logs into the developer's hosting panel from another country. The cookie bypassed the password and MFA, so changing only the password would not have helped until active sessions were revoked.
How it differs
An infostealer takes what is already stored, in a short run. A keylogger records what is typed, over time. Magecart style skimmers steal card data from a web page rather than from the visitor's computer. Stolen session cookies are why an infostealer can defeat MFA, which a plain phished password cannot.
Common errors
Changing a password without logging out other sessions. Assuming MFA stops it. Cleaning the machine but not rotating every saved secret. Running cracked software on a work machine. Saving production keys in browser password managers or plain `.env` files.
In practice
If a machine might have run an infostealer, wipe it, then rotate every credential and invalidate every session and API key that machine could touch. Keep deploy keys out of the home directory and use a hardware key for important logins.