A CISO's guide to infostealers: Prevention and detection | TechTarget

https://www.techtarget.com/rms/onlineimages/legal_g511600871.jpg

Infostealers do exactly as their name implies: The malware secretly steals sensitive information, such as passwords and financial information, from user endpoints and then transfers that information to a location selected by the attacker.

Infostealers have become far more prevalent in recent years, underpinning dark web markets where attackers actively buy, sell and trade the sensitive data they acquire. Unlike ransomware, where attackers draw attention in hopes of soliciting ransom payments, infostealers do their thievery in silence.

Let's examine how infostealers work to provide CISOs, security leaders and practitioners with infostealer prevention and detection recommendations.

How infostealers work

Infostealers typically employ a botnet architecture. Under a malware-as-a-service model, attackers essentially rent or subscribe to infostealers, configure them as desired and then launch attacks against endpoint targets. Attack methods vary widely, ranging from phishing attacks and malicious links to social engineering and silent drive-by downloads.

Successful attacks infect user endpoints, which...

Copyright of this story solely belongs to techtarget.com. To see the full text click HERE

Read more