Infostealers and the Credential Economy
- Infostealers grab everything valuable and exfiltrate in seconds: browser passwords, session cookies, autofill, crypto wallets, tokens (Discord, etc.), files.
- Common families: RedLine, Raccoon, Lumma (LummaC2), Vidar, Stealc — mostly sold as MaaS (Malware-as-a-Service) subscriptions.
- Why cookies matter: a stolen session cookie can bypass passwords and MFA — the attacker replays your logged-in session.
- The economy: stolen data is packaged into "logs" and sold on marketplaces; those logs feed account takeover, fraud, and the initial access that leads to ransomware.
Key Takeaway
One stealer run can convert a single infection into dozens of compromised accounts — and often the first step of a bigger breach.