What exactly is an infostealer?
It is a small program with one job: open everything on the machine that holds a secret, copy it, send it out and leave. It is not ransomware and does not want your attention. Most builds finish in under a minute and delete themselves.
The list it works through is short and well known. Saved passwords in every browser profile, session cookies, authentication tokens, cryptocurrency wallet files, messenger data, and a screenshot of the desktop for context.
It arrives through ordinary routes. A cracked application, a game modification, a fake installer for something legitimate, an attachment, a browser extension that changed hands. The delivery is dull because it does not need to be clever.
Vidar, StealC and Lumma have been the three most prolific families through 2026. The names matter less than the fact that more than thirty of them are on sale at any time, rented by people with no technical skill at all.
What comes out the other end is a file listed for sale within hours, described by country, by which banks appear in it and by how fresh the sessions are. The person who infected your machine is rarely the person who eventually uses what was taken, which is why the account trouble often starts weeks after the infection.
