Open cardosec

Case E15B7D · Malware & intel · L3 Applied

Infostealers

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Stealers like RedLine, Lumma, Vidar and Raccoon are sold as MaaS and spread via cracks, malvertising, fake updates
  2. They grab browser passwords, cookies, autofill, crypto wallets, and tokens for Discord, Telegram, Steam
  3. Chromium secrets are protected by DPAPI; running as the user lets the stealer decrypt them locally
  4. Stolen session cookies bypass MFA; logs are sold on markets and Telegram and fuel later breaches
  5. Response: revoke all sessions and tokens, rotate creds from a clean device, not just reset the password

If the interviewer pushes back

  • How did Chrome App-Bound Encryption change stealer tradecraft, and how did stealers adapt?
  • Why did infostealer logs play a central role in the 2024 Snowflake customer breaches?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.