Infostealer malware is often described as a password-theft problem. That description is no longer sufficient. Modern information stealers can extract browser credentials, session cookies, authentication tokens, payment-card data, cryptocurrency wallet information, private documents, messaging data and detailed information about the infected device.
The resulting collection, commonly packaged as a stealer log, can provide criminals with much of what they need to impersonate the victim across personal, financial and corporate services. One infection may expose online banking, email, cloud platforms, social-media accounts, remote-access services and cryptocurrency wallets simultaneously.
For financial crime teams, the significance lies in what happens after the theft. Stolen identity and authentication data can enable account takeover, unauthorised payments, business email compromise, investment fraud, cryptoasset theft, synthetic identity activity, mule-account control, data extortion and ransomware. The malware infection is therefore not the complete crime. It is the acquisition stage of a wider criminal supply chain.
Listen the podcast
Watch the video
Why infostealer malware matters now
The scale of the underground credential economy has increased materially. FortiGuard Labs reported that, during 2024, logs from systems compromised by infostealer malware increased by 500%, with 1.7 billion stolen credential records shared through underground forums. It also observed a 42% rise in compromised credentials offered for sale more broadly. The original headline should therefore be read carefully: the figure refers to credential records rather than necessarily 1.7 billion unique individuals or passwords.
Enforcement activity provides further evidence of the scale. In May 2025, Microsoft and international partners disrupted infrastructure associated with Lumma Stealer, a malware-as-a-service operation used by hundreds of threat actors. Microsoft identified more than 394,000 infected Windows devices during a two-month period and took action against approximately 2,300 malicious domains. The US Department of Justice stated that the FBI had identified at least 1.7 million instances in which LummaC2 had been used to steal information.
These numbers matter because stolen credentials are not static breach artefacts. Fresh stealer logs can include the website accessed, username, password, active session, browser profile, device characteristics and supporting personal information. This contextual package can be more valuable than a password obtained from an older database breach because it helps the buyer reproduce the victim’s normal digital environment.
The risk also crosses the boundary between personal and professional devices. Employees may access corporate email, cloud platforms or remote-working services from unmanaged computers that also contain personal accounts, browser extensions, gaming software and downloaded files. A household device infected through cracked software or malicious advertising can therefore become an entry point into a regulated institution.
How infostealers reach the victim
Infostealers are commonly delivered through phishing attachments, malicious links, fake software installers, cracked applications, poisoned search results, fraudulent advertisements and compromised websites. The victim may believe they are downloading a legitimate browser update, productivity tool, game modification, artificial-intelligence application or document.
The malware does not always require long-term persistence. Some variants execute quickly, collect available information, transmit it to criminal infrastructure and remove themselves. The victim may notice no obvious deterioration in device performance, and endpoint-security tools may detect the infection only after the data has already left the device. The Australian Cyber Security Centre warns that information stealers are designed to operate without detection and may delete themselves after collecting information.
Criminal distribution is increasingly professionalised. Lumma, for example, was marketed as malware-as-a-service, allowing affiliates to deploy a maintained credential-stealing product without developing their own malware. Its operators continually released updated versions, while affiliates distributed it through phishing, impersonation and malicious advertising campaigns.
This division of labour reduces the technical barrier to entry. Malware developers maintain the tool, distributors obtain infections, log-market operators organise the stolen data, access brokers identify valuable credentials, and downstream criminals conduct the account takeover, fraud or extortion.
What a stealer log can contain
The term “password stealer” understates the breadth of the collection. Government guidance identifies credentials, browser history, session cookies, autofill data, saved payment-card details, email and messaging content, documents, cryptocurrency wallets, private keys, screenshots, IP addresses, installed applications and information about the device’s security controls among the potential targets.
This combination allows criminals to build a detailed digital identity profile. Email access may reveal invoices, financial relationships, personal communications and password-reset messages. Browser history can identify the banks, exchanges, marketplaces and corporate systems used by the victim. Autofill records can expose names, addresses and payment details. Cryptocurrency seed phrases may provide direct control over virtual-asset wallets.
Session cookies and tokens are particularly important. After a user successfully authenticates, many services issue a token that allows the session to continue without requiring the password and second factor for every action. If that token is stolen and remains valid, a criminal may be able to replay the authenticated session.
This means that changing a password may not fully remove the attacker. The institution may also need to invalidate active sessions, revoke tokens, review registered devices and re-establish trusted access. Government guidance consequently recommends enforcing expiry policies for session tokens and cookies as part of organisational protection against infostealer exploitation.
How stolen data becomes financial crime
The most immediate pathway is account takeover. Criminals can test stolen credentials against the bank, payment provider, crypto exchange or merchant identified in the log. Where the victim reused passwords, the same credential combination may provide access to additional services.
Verizon reported that compromised credentials were the initial-access vector in 22% of the breaches reviewed in its 2025 Data Breach Investigations Report. Its analysis of infostealer data also found that, in the median case, only 49% of an infected user’s passwords across different services were distinct. This level of reuse makes one device infection capable of exposing several accounts.
Email compromise can expand the attack. An offender may search the inbox for banking relationships, invoices, cryptocurrency transactions or conversations with colleagues and suppliers. The account can then be used to reset other passwords, impersonate the victim, redirect payments or launch business email compromise against trusted contacts.
Financial accounts may be used for direct theft, but they can also support wider laundering. Criminals may change beneficiary details, initiate transfers, enrol new devices, access stored card information or take control of accounts later used to receive and disperse criminal proceeds. A compromised genuine account may appear less suspicious than one opened using fabricated information.
Cryptocurrency information can be monetised rapidly. A seed phrase or private key can give an attacker control over the wallet itself, while access to an exchange account may allow assets to be transferred, converted or withdrawn through criminally controlled destinations.
Corporate credentials create another route. Google’s Mandiant investigated a campaign in which threat actors used credentials previously obtained through infostealer infections to access customer-managed cloud database accounts. Approximately 165 potentially exposed organisations were notified, and some of the credentials had remained valid since infections dating back to 2020.
The campaign demonstrates an important control failure: stolen credentials can retain value for years where they are not rotated, protected by multi-factor authentication or restricted by network and device controls.
Why the criminal model scales efficiently
The first reason is automation. Malware can collect information from thousands of devices, organise it into standardised logs and upload it to criminal infrastructure with limited manual intervention.
The second reason is specialisation. The person who infects the device does not need to conduct the final fraud. Logs can be sold to actors specialising in online banking, cryptocurrency theft, corporate access, social-media takeover or ransomware.
The third reason is contextual richness. Traditional credential lists may contain only an email address and password. A stealer log may reveal the services used by the victim, the device configuration and an active authenticated session. This reduces the buyer’s reconnaissance burden.
The fourth reason is credential longevity. Organisations may focus on recent breaches while overlooking historical malware exposure. The Snowflake-related campaign showed that credentials stolen years earlier remained usable because they had not been rotated.
The fifth reason is the separation between detection domains. Cybersecurity teams may see malware alerts, identity teams may see unusual logins, fraud teams may see payment anomalies and AML teams may see funds moving through mule accounts. If those signals are not connected, each team observes only one stage of the criminal chain.
Why infostealer-enabled fraud is difficult to detect
The attacker may authenticate with the correct credentials, use an existing session and possess enough information to answer security questions or impersonate the customer convincingly. The activity can therefore resemble legitimate access.
Geolocation is not always decisive. Criminals can use residential proxies or infrastructure geographically close to the victim. Device fingerprints may also be partially reconstructed from data contained in the log.
A successful second-factor event does not eliminate the risk. The customer may have approved an authentication prompt through social engineering, or the attacker may be reusing a session token created after an earlier legitimate authentication. Multi-factor authentication remains essential, but the institution must assess the strength of the method and the security of the session that follows it.
Credential-stuffing traffic can also blend into ordinary authentication volume. Verizon found that such activity represented a median of 19% of daily authentication attempts in the single-sign-on data it analysed, increasing to 25% for enterprise-sized organisations.
The strongest detection models therefore analyse identity, device, session and transaction behaviour together. A login may appear acceptable in isolation but become materially more suspicious when followed by a password change, new-device registration, beneficiary creation, contact-detail amendment and rapid transfer.
What a resilient control stack looks like
The first layer is device security. Organisations should maintain supported operating systems, endpoint protection, application controls and rapid patching. Staff should be trained to recognise malicious downloads, fake browser updates, poisoned search results and fraudulent advertisements.
The second layer is strong identity assurance. Multi-factor authentication should be applied to banking, email, remote access, cloud services and privileged accounts. Phishing-resistant authentication, including FIDO-based security keys and passkeys, provides stronger protection than reusable passwords and message-based codes. CISA recommends phishing-resistant MFA as the preferred approach for high-value accounts.
The third layer is session governance. Institutions should shorten unnecessary session lifetimes, apply risk-based reauthentication, revoke sessions after material account changes and bind access more closely to trusted devices. Session tokens should not remain valid indefinitely after a password reset or compromise event.
The fourth layer is behavioural monitoring. Controls should identify impossible or unusual travel, concurrent sessions, unfamiliar devices, abnormal navigation, unexpected credential changes and high-risk actions that depart from the customer’s established behaviour.
The fifth layer is credential-exposure intelligence. Institutions can use lawfully obtained threat intelligence to identify customer, employee and third-party credentials appearing in stealer logs or criminal markets. Exposure should trigger risk-based investigation rather than an automatic conclusion that fraud has occurred.
The sixth layer is transaction protection. High-risk authentication events should influence payment decisioning. A suspicious session followed by beneficiary creation, crypto purchase, card enrolment or rapid funds movement should generate stronger intervention than either signal alone.
Finally, financial institutions need integrated cyber-FinCrime response. Confirmed infostealer exposure should be shared with fraud, identity, AML, cybersecurity and incident-response teams. Investigators should review not only the compromised account but also beneficiaries, linked devices, mule networks and any subsequent movement of funds.
What an effective compromise response looks like
Removing the malware is only the beginning. The affected device should be isolated, examined and rebuilt where appropriate. Credentials should be changed from a trusted, clean device, beginning with email, banking, cloud, password-management and administrative accounts.
Active sessions and authentication tokens should be invalidated. Registered devices, recovery addresses, forwarding rules, application permissions and recent security changes should be reviewed. Financial transactions, beneficiaries, card enrolments and cryptocurrency withdrawals should be checked for unauthorised activity.
Organisations should identify every business credential that may have been stored or used on the infected device. This includes VPN access, remote desktop, cloud administration, developer tokens, privileged accounts and third-party services. The response should consider the complete exposed identity, not only the credential that first triggered the alert.
Customers also require clear communication. A generic instruction to reset one password may create false reassurance where session cookies, other credentials or financial information have also been stolen.

What this means for financial crime leaders
Infostealer malware should not be governed solely as an endpoint-security issue. It is a source of criminal identity intelligence and a precursor to multiple forms of fraud, money laundering and cyber-enabled financial crime.
Leaders should ask whether their institution can connect malware exposure with account authentication, customer behaviour, payment activity and receiving-account risk. They should also determine whether an incident involving a personal or contractor device can trigger appropriate review of corporate accounts and privileged access.
The central strategic shift is from password security to identity compromise. A criminal who possesses the password, session, device profile and supporting personal data may be able to impersonate the customer more effectively than a conventional fraud model anticipates.
The 1.7 billion credential records observed in underground forums are not merely evidence of past leakage. They represent a reusable inventory of digital identities that can be tested, enriched, sold and weaponised across the financial system.
The institutions best positioned to respond will be those that treat every infostealer infection as a potential financial-crime event, neutralise the full exposed identity and connect cyber intelligence with fraud prevention before stolen access is converted into stolen funds.




Infostealer malware is no longer a narrow cybersecurity problem focused on stolen passwords. It has become a foundational component of the wider financial-crime ecosystem, supplying criminals with credentials, session tokens, payment information, identity data and device intelligence that can be reused across multiple fraud and laundering pathways.
The most significant risk lies in the combination of these stolen elements. A criminal who possesses a password, active session, device profile and supporting personal information may be able to imitate a legitimate customer with far greater precision than traditional fraud controls anticipate. This enables account takeover, unauthorised payments, business email compromise, cryptoasset theft and the misuse of genuine accounts as part of mule and laundering networks.
Effective defence therefore requires more than password resets or endpoint remediation. Institutions must revoke active sessions, review trusted devices, reassess recovery channels, monitor subsequent payment activity and connect malware exposure with identity, fraud, AML and cyber intelligence.
The strongest control frameworks will treat confirmed infostealer exposure as a potential financial-crime event. They will combine phishing-resistant authentication, session governance, device intelligence, behavioural monitoring and rapid compromise response to neutralise the full exposed identity.
Ultimately, the value of stolen credentials lies in how quickly they can be converted into access, influence and funds. Financial institutions that connect cyber indicators with transactional risk before that conversion occurs will be better positioned to prevent losses, disrupt downstream criminal activity and protect both customers and the wider financial system.