What is an information stealer?¶
An information stealer is malware designed to collect valuable data from a device or user profile.
Targets may include browser credentials and session material, digital-wallet material, payment details, email or messaging data, documents and system information. The useful investigation follows the data from local access to staging, transfer and any later misuse.
A browser-profile event makes the stages visible¶
Suppose endpoint telemetry on a Windows laptop shows an unrecognised process opening browser-profile databases, creating a temporary archive and then sending data to an external service.
A capability report describes what the malware could target. Incident records establish what it reached, packaged, transmitted and enabled in this case.
The example is fictional and provider-neutral. It shows the kinds of joins an investigator should expect rather than one product's fixed schema.
Keep five propositions separate¶
| Stage | What may support it |
|---|---|
| Stealer present | File, memory, process or security-tool evidence |
| Stealer executed | Process, memory and child-process records |
| Data accessed or collected | File/database access, recovered output or staging artefact |
| Data transferred | Network flow, proxy, captured content or matching service-side record |
| Data used later | Account session, token use, reset, payment or fraud evidence linked in time and detail |
The device may not contain the targeted data. Encryption or operating-system controls may prevent access. A staging archive may be created but never transmitted. A successful transfer does not prove that every possible item was included.
Later account activity is valuable corroboration¶
If an unfamiliar account session follows the stealer event, compare:
- the affected account and exact time window;
- whether the session used a password, cookie, token or recovery route;
- device and client details in the provider record;
- security changes, new sessions and actions after access; and
- other realistic theft routes, including phishing or an earlier breach.
A stolen session or token can allow access without a fresh password entry. The later event can strongly support the incident sequence when its timing and account context align, but it remains a separate evidential stage.
Preserve the affected browser profiles, credential stores and volatile evidence before cleanup where the authorised forensic route allows. Remediation can remove the local collection and staging evidence needed to explain what happened.
Set out the last supported stage explicitly: presence, execution, local collection, transfer or later misuse. Each additional joined stage strengthens the incident account without turning a possible target or capability into a completed theft.