Live Threat Pulse: 2,847 threats detected in last 24h

menu_book Reference

Infostealer
Glossary

A field reference to the infostealer threat landscape — the malware families, stolen-data formats, and credential-theft tactics that define the cybercrime supply chain. Each entry explains what it is, why it matters, and how VantaPrism tracks it.

71 terms indexed

Malware Family Profiles

30
Acreed Stealer arrow_outward

Acreed is a newer infostealer that rose in prominence as a replacement for disrupted families, harvesting browser credentials,…

Agent Tesla arrow_outward

Agent Tesla is a long-established .NET-based infostealer and remote access tool that logs keystrokes, captures screenshots, and…

Arkei Stealer arrow_outward

Arkei is an older infostealer that served as the basis for the Vidar family. It collected browser data, cookies, and cryptocurr…

Atomic macOS Stealer (AMOS) arrow_outward

Atomic macOS Stealer (AMOS) is an infostealer targeting Apple macOS systems. It steals keychain passwords, browser credentials…

Aurora Stealer arrow_outward

Aurora Stealer is a Go-based infostealer that was marketed as a multi-purpose botnet and stealer, harvesting browser credential…

AZORult arrow_outward

AZORult is a veteran infostealer and downloader that harvests browser credentials, cookies, cryptocurrency wallets, and files.…

Banking Trojan arrow_outward

A banking trojan is malware designed to steal financial credentials and manipulate online banking sessions, often via web injec…

FormBook / XLoader arrow_outward

FormBook is a malware-as-a-service infostealer that grabs credentials from browsers and applications, logs keystrokes, and can…

Kraken Stealer arrow_outward

Kraken is an infostealer marketed on underground channels that harvests browser credentials, cookies, cryptocurrency wallets, a…

Lumar Stealer arrow_outward

Lumar is a lightweight C-based infostealer sold cheaply on underground forums that collects browser credentials, cookies, crypt…

Lumma Stealer (LummaC2) arrow_outward

Lumma Stealer (LummaC2) is a malware-as-a-service infostealer that steals browser credentials, cookies, cryptocurrency wallets,…

Mars Stealer arrow_outward

Mars Stealer is an infostealer derived from the older Oski stealer that targets browser credentials, cookies, cryptocurrency wa…

Meduza Stealer arrow_outward

Meduza Stealer is a Windows infostealer marketed on underground forums that collects browser credentials, cookies, password man…

MetaStealer arrow_outward

MetaStealer is an infostealer derived from the RedLine codebase that targets browser credentials, cookies, autofill data, and c…

Nexus Stealer arrow_outward

Nexus is an infostealer offered as a service that targets browser-stored credentials, cookies, autofill, and cryptocurrency ass…

Oski Stealer arrow_outward

Oski is an older infostealer notable as the predecessor of Mars Stealer. It harvested browser credentials, cookies, and cryptoc…

Phemedrone Stealer arrow_outward

Phemedrone is an open-source-derived infostealer that targets browsers, cryptocurrency wallets, messaging apps, and password ma…

Poseidon Stealer arrow_outward

Poseidon is a macOS-targeting infostealer marketed as an Atomic (AMOS) competitor. It steals keychain data, browser credentials…

Predator the Thief arrow_outward

Predator the Thief is an infostealer sold on Russian-speaking forums that steals browser data, cookies, cryptocurrency wallets,…

Raccoon Stealer arrow_outward

Raccoon Stealer is a malware-as-a-service infostealer that harvests passwords, cookies, autofill data, and cryptocurrency walle…

Raccoon Stealer V2 arrow_outward

Raccoon Stealer V2 (also tracked as RecordBreaker) is the rewritten successor to the original Raccoon, built in C/C++ for perfo…

RedLine Stealer arrow_outward

RedLine Stealer is an information-stealing malware (infostealer) sold as malware-as-a-service that harvests saved browser crede…

Remote Access Trojan (RAT) arrow_outward

A remote access trojan (RAT) is malware that gives an attacker remote control of an infected device. Many RATs include infostea…

Rhadamanthys Stealer arrow_outward

Rhadamanthys is an advanced, modular infostealer sold as malware-as-a-service that steals credentials, cookies, cryptocurrency…

RisePro Stealer arrow_outward

RisePro is an infostealer that shares similarities with the Vidar family and is distributed through pay-per-install loader serv…

Snake Keylogger arrow_outward

Snake Keylogger is a .NET-based credential stealer and keylogger that records keystrokes, captures screenshots and clipboard da…

StealC arrow_outward

StealC is a lightweight malware-as-a-service infostealer, influenced by Vidar and Raccoon, that steals browser data, cookies, c…

Taurus Stealer arrow_outward

Taurus is an infostealer linked to the same actors behind the Predator the Thief family. It harvests browser credentials, cooki…

Vidar Stealer arrow_outward

Vidar is a long-running infostealer, derived from the older Arkei stealer, that collects browser credentials, cookies, cryptocu…

ViperSoftX arrow_outward

ViperSoftX is a long-running information stealer and loader that specialises in cryptocurrency theft, including clipboard hijac…

Concepts

23
Account Takeover (ATO) arrow_outward

Account takeover (ATO) is when an attacker gains unauthorized control of a legitimate user account, typically using stolen cred…

Attack Surface arrow_outward

An attack surface is the total set of points where an attacker could attempt to enter or extract data from a system. Compromise…

Business Email Compromise (BEC) arrow_outward

Business email compromise (BEC) is a fraud in which attackers gain access to or impersonate a corporate email account to trick…

Command and Control (C2) arrow_outward

Command and control (C2) is the infrastructure attackers use to communicate with malware on infected devices — issuing instruct…

Compromised Credentials arrow_outward

Compromised credentials are usernames and passwords that have been exposed to unauthorized parties — frequently through infoste…

Credential Monitoring arrow_outward

Credential monitoring is the continuous practice of watching for an organisation's usernames and passwords appearing in breache…

Dark Web Monitoring arrow_outward

Dark web monitoring is the practice of continuously searching dark-web markets, forums, and channels for an organisation's expo…

Data Breach arrow_outward

A data breach is an incident in which sensitive data is accessed or disclosed without authorisation. Infostealer infections are…

Ethical Disclosure arrow_outward

Ethical disclosure is the practice of responsibly notifying an organisation that its data or credentials have been exposed — fo…

Infostealer Malware arrow_outward

Infostealer malware is a category of malicious software designed to silently harvest sensitive data — passwords, session cookie…

Initial Access Broker (IAB) arrow_outward

An initial access broker (IAB) is a cybercriminal who sells access to compromised networks and accounts to other attackers, suc…

Loader Malware arrow_outward

Loader malware (a loader or dropper) is software whose job is to install other malware on a compromised device. Loaders frequen…

Log Cloud arrow_outward

A log cloud is a subscription service — usually run through Telegram channels or dark-web panels — that gives criminal buyers c…

Malware-as-a-Service (MaaS) arrow_outward

Malware-as-a-service (MaaS) is a criminal business model in which malware authors rent or sell their software, infrastructure,…

MFA Bypass arrow_outward

MFA bypass is any technique that defeats multi-factor authentication so an attacker can access an account despite the extra fac…

OPSEC (Operational Security) arrow_outward

OPSEC (operational security) is the discipline of protecting information and activity from adversaries by controlling what is e…

OSINT (Open-Source Intelligence) arrow_outward

OSINT (open-source intelligence) is intelligence gathered from publicly available sources. In cybercrime investigations, OSINT…

Pay-Per-Install (PPI) arrow_outward

Pay-per-install (PPI) is a criminal service model where operators are paid to install other actors' malware on compromised mach…

Ransomware arrow_outward

Ransomware is malware that encrypts or steals a victim's data and demands payment for its return. Infostealer-harvested credent…

Telegram in Cybercrime arrow_outward

Telegram has become a central marketplace and distribution channel for cybercrime, especially infostealer logs. Threat actors u…

Third-Party / Supply Chain Risk arrow_outward

Third-party (supply chain) risk is the security exposure an organisation inherits from its vendors, partners, and suppliers. In…

Threat Intelligence arrow_outward

Threat intelligence is evidence-based knowledge about threats — actors, tactics, and indicators — used to inform defensive deci…

Zero Trust arrow_outward

Zero trust is a security model that assumes no user or device is inherently trusted and verifies every access request continuou…

Tactics

9

Data Types

9

Is your organization in the logs?

These threats produce stealer logs every day. Find out whether your domains, employees, or customers appear in infostealer data — before adversaries exploit it.

Generate a Threat Report arrow_forward