When a business gets breached, everyone wants to know which clever hacker picked the lock. Usually nobody picked anything. Somebody just walked in with a key that was quietly copied off an employee’s laptop weeks earlier.

That copying is done by a category of malware called an infostealer. It is not dramatic. It does not lock your files or pop up a ransom note. It lands on one computer, quietly gathers up everything that machine uses to prove who it is, sends that bundle off, and often deletes itself. Weeks or months later, somebody else uses the contents to log into your accounting system as your office manager. Here is how the whole thing works and, more usefully, how to make it not work on you.

What This Malware Actually Takes

Think of your work computer as a desk with a drawer full of spare keys. Over the years you have put a lot in that drawer without thinking about it. Infostealers open the drawer and photograph the whole thing.

In a joint advisory published in 2025, the FBI and CISA described a widely used infostealer and listed what it pulls off an infected machine: personally identifiable information, financial credentials, cryptocurrency wallets, browser extension data, and multifactor authentication details. In plain terms, that means:

  • Saved passwords. Everything anyone clicked “save password” on in the browser, going back years, for accounts nobody remembers having.
  • Session cookies. The small files your browser keeps so you stay logged in. These are the dangerous ones, and we will come back to them.
  • Autofill data. Names, addresses, phone numbers, and in plenty of cases card details that a browser was helpfully remembering.
  • Files that look valuable. Documents matching certain patterns, sitting in obvious folders like the desktop and downloads.
  • Machine details. Enough about the computer itself to help someone impersonate it later.

All of it, from one machine, in the time it takes to make coffee.

Where These Infections Come From

Almost nobody gets hit by an infostealer while doing something they knew was risky. They get hit while trying to do something ordinary. The FBI and CISA advisory published in 2025 named spearphishing emails with malicious attachments and links, and spoofed versions of popular software such as media players and utilities, among the common delivery methods.

The patterns worth teaching your team to recognize:

  • Cracked or “free” versions of paid software. This is the classic. Someone needs a PDF editor, does not want to ask for a license, and finds a free copy. The free copy is free for a reason.
  • Fake download pages. A search for a legitimate program returns a paid ad above the real result, pointing at a lookalike site with a lookalike installer. The software often even works.
  • Malicious ads on ordinary websites. No sketchy browsing required. Ad networks get abused, and the ad does the work.
  • Fake verification prompts. A page claims you need to prove you are human, then asks you to copy something and paste it somewhere on your own computer. No legitimate website has ever needed you to do that. If a site asks, close the tab.
  • Attachments and links in convincing email. The delivery method that never goes out of style, which is why we wrote separately about the surge in phishing attacks and why blocking them stays hard.

How Your Passwords End Up For Sale

Here is the part that surprises owners. The person who infected the laptop is usually not the person who eventually logs into your systems. They are a supplier.

The harvested bundle from a single machine gets packaged and sold on criminal marketplaces, sometimes many times over. Buyers search those collections the way you would search a spreadsheet, looking for the domain of a bank, a payroll provider, or a business they already intend to hit. Your employee’s credentials might sit in a database for months before anyone bothers with them. That delay is why the login that drains an account rarely lines up with anything memorable that happened that week. The infection and the incident are separate events with different people involved.

Why Changing the Password Might Not Close the Door

This is the single most important thing in this article, so we will be direct about it. Changing a password after an infostealer infection is necessary and often insufficient.

Remember those session cookies. When you log into a system and check the box to stay signed in, the site hands your browser a token that says “this person already proved who they are.” A stolen token can be loaded somewhere else and used as is. It does not require your password, because the password step already happened. It does not usually require a code from your phone, for the same reason. That is how attackers get past ordinary multifactor authentication without ever seeing a code.

So if you reset the password but leave the old sessions alive, you have changed the lock and left the guy who is already inside standing in the hallway. Every serious platform has a control, usually near the security or active sessions area of the account settings, that revokes all existing sessions and forces everyone to sign in again. Use it. Every time.

The Defenses That Actually Move the Needle

None of this requires an enterprise budget. It requires deciding to do five things and then actually doing them.

  1. Run real endpoint detection, monitored by someone. The FBI and CISA advisory published in 2025 recommends monitoring and detecting suspicious behavior and unusual processes. Traditional antivirus that only recognizes known bad files is not enough on its own, and detection with nobody watching the alerts is just a log file.
  2. Stop storing work passwords in the browser. Browser password stores are the first drawer this malware opens. Move the company to a proper password manager, then go through each browser profile and clear out what is saved there. Turn off the offer to save going forward.
  3. Use phishing resistant multifactor authentication on anything that matters. CISA has stated that not all forms of MFA are equally secure and strongly urges organizations to implement phishing resistant MFA. Hardware security keys and passkeys are the strongest options available to a small business. We compared them plainly in our post on YubiKey vs passkey vs MFA.
  4. Control what can be installed. The same 2025 FBI and CISA advisory recommends application controls including allowlisting. Even the basic version helps: staff work from standard accounts rather than administrator accounts, and software requests go through you. This alone kills the cracked software problem.
  5. Treat an infected machine as fully compromised. Not cleaned. Compromised. Take it off the network, rebuild it from a known good image, then rotate credentials and revoke sessions for every account that touched it. Removing the malware does not un-steal what already left.

The Bottom Line

Infostealers are boring, which is exactly why they work. There is no ransom note to force a decision and no dramatic moment to point at. One laptop gets infected, a drawer full of keys gets copied, and the consequence arrives months later wearing your employee’s name.

The defenses are unglamorous and they are effective. Get passwords out of browsers. Put strong multifactor authentication on the accounts that would hurt to lose. Have someone watching your endpoints. Control installs. And when something does get through, assume the machine gave up everything, because it did.

If you are not sure whether your current setup would catch this, or you want a straight answer about where your company’s saved passwords are living right now, we are happy to take a look. We work with small and mid sized businesses across Denton County and we will tell you plainly what needs fixing and what does not. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).