One of the greatest targets for cybercriminals is information and they are always looking for the best and most advanced ways to obtain it. One of the most insidious ways to do this is with the use of stealer malware. Also known as information-stealing malware, this type of malware has been in use for nearly 20 years—and that use is on the rise, making it critical that organizations know how to protect themselves against it. Let’s do a deep dive into what stealer malware is and how to protect your company.
What Is Stealer Malware?
Stealer malware is malware that is specifically designed to steal confidential or sensitive information. This includes information such as:
- Login credentials
- Personal information (name, address, phone number, Socia Security/Insurance Number)
- Banking and financial information (bank account numbers, credit card information)
- Proprietary information (intellectual property, corporate secrets)
- Email attachments and contents
- Browser history and cookies
It’s easy for cybercriminals to purchase monthly subscriptions for stealer malware from the dark web. It’s also easy for cybercriminals to create their own stealer malware because it is easy to write, and the source code for this type of malware is readily available online. Add to this the fact that the overhead costs are low and the theft of information a lucrative business for many.
How Stealer Malware Works
Stealer malware uses a variety of techniques to gain access to information. These include:
- Logging keystrokes to collect sensitive information such as usernames and passwords
- Taking screenshots that contain information such as banking transactions
- Gaining access to databases that contain confidential information
- Hijacking emails that the attacker can then read and from which they can extract information
There are a few ways stealer malware can get installed on a system. The most common of these are:
- Phishing emails – A phishing email is a fake email sent by the attacker that looks genuine. This type of email contains a malicious link to click or file to download, and when the recipient does so, the malware is installed.
- Compromised websites – Some websites are compromised or set up to be malicious. Once you visit the site, the malware can be automatically uploaded to your computer or system, often without you clicking on anything.
- Free software downloads – While not all free software is bad, you need to be careful. If the website is questionable or the software is pirated, it might contain stealer malware.
Most Common Stealer Malware Variants
There are many variants of stealer malware that are available to and used by cybercriminals. The most common of these are:
- Raccoon – This targets login credentials, particularly those for online shopping platforms, and steals financial information.
- RedLine – This targets credit card information and browser history to steal financial information and commit identity theft.
- Vidar – This targets employee login credentials, allowing the attacker access to a company’s network and systems.
- BlackGuard – This targets login credentials, browser history, financial information, and cryptocurrency wallets to steal related data.
How to Protect Against Stealer Malware
There are several ways to protect your organization from stealer malware. First and foremost, it is critical that you ensure every person who works for your company understands that they play a part in keeping the organization safe. Cybersecurity is everyone’s responsibility. With this in mind, to keep your company safe, you can do the following:
- Educate and train employees – Make sure all employees are educated on how to recognize a phishing attack and what to do if they think they’ve clicked on a link or downloaded an attachment from a suspicious email.
- Install antivirus/antimalware software – Ensure that you have the most up-to-date antivirus and antimalware software installed.
- Implement a strong password policy – Require all employees to create long, complex passwords for their accounts and have them reset those passwords regularly.
- Use multifactor authentication (MFA) – Make it a requirement that all users that have access to the system must use two or more methods of authentication to gain access. This can be any combination of username/password, biometric authentication, codes, and passkeys to prove they are who they say they are.
- Manage cookie policies – Set shorter cookie expiration times and ensure that, when a cookie has been compromised, the session is invalidated. Enforce a password reset for any users who have been compromised.
- Device management – Ensure that all personal devices and corporate devices that access company network, systems, and data are secured and that you have a strong BYOD policy in place.
- Back up data – Regularly back all your organizational data, so if your company is ever compromised via stealer malware, you can easily retrieve it and ensure business continuity.
Next to your employees, your information is your company’s greatest asset. Protecting it means protecting your employees, your customers, your financial wellbeing, and your reputation. A trusted cybersecurity partner can go a long way to keeping your sensitive information safe. At Platinum Technologies, we offer a consulting and advisory service and a full security assessment to help you identify weaknesses in your cybersecurity, so you can develop an action plan to strengthen your cybersecurity posture and ensure regulatory comp



