Start with Identity
← Glossary
Threat

Infostealer

Malware that harvests credentials, cookies, and session tokens from infected devices, then sells them. A major driver of recent account-takeover and session-theft growth.

Infostealers changed the economics of account takeover: the credential is stolen once from an endpoint and resold repeatedly, often working years later because nobody rotated it. They also take session cookies, which is why the theft survives a password reset and defeats MFA that was only enforced at login. The Snowflake campaign is the canonical case, built entirely on infostealer logs against accounts without MFA.

See also: token theft, session hijacking, account takeover, Snowflake 2024 credential attacks

Last reviewed By SWI Community TeamSuggest a correctionHow we research