Stopping infostealers before they do the damage

A staff member at a Brisbane professional services firm downloads what looks like a software update on their home laptop. Within minutes, a lightweight program has lifted every saved browser password, a handful of active session cookies for Microsoft 365, and the credentials to the firm’s cloud accounting tool. Nobody notices. Three weeks later, the firm’s Microsoft 365 tenant is accessed by a threat actor who never needed to guess a single password. That is the infostealer pattern in 2026, and it is now the most common doorway into Australian SME networks.
If you want to understand the full picture of credential-based attacks, our overview of account takeover is a good place to start. This article focuses on stopping infostealers before they hand over the keys.
What infostealers actually do
An infostealer is malware built for one job: harvest credentials and get out undetected. It targets saved browser passwords, active session cookies, authentication tokens, and sometimes crypto wallet keys. The stolen data gets packaged into a compressed file called a “log” and sent back to the attacker’s server.
The session cookie piece is the part most people miss. A session cookie proves to an application that you are already logged in. If an attacker injects a stolen cookie into their own browser, they bypass authentication entirely, no password needed, no multi-factor authentication (MFA) prompt triggered. MFA alone does not stop thisbecause the attacker is not logging in. They are resuming a session that already passed the login check.
Infostealers rarely end there. Stolen data gets sold on underground forums to Initial Access Brokers (IABs), who on-sell access to ransomware groups. The time between a credential appearing on a dark-web log marketplace and a ransomware attack can be under 48 hours. That is the pipeline, and infostealers are the first step.
Why the threat has grown sharply
Infostealers grew into the fastest-growing malware category in 2025, overtaking ransomware in terms of deployment volume. The reason is the business model: operators rent ready-built tools under a malware-as-a-service (MaaS) model, often for under $100 per month. Low cost plus a reliable market for stolen logs means more operators at more skill levels.
The scale is significant. Flashpoint reported that infostealers contributed to the theft of over 1.8 billion credentials from nearly 5.8 million infected devices in the first half of 2025. Microsoft Entra ID credentials showed up in 79% of infostealer logs examined in 2026 research, a direct signal for businesses running Microsoft 365. And according to the 2025 Verizon Data Breach Investigations Report, 32% of breaches globally involved stolen credentials, most sourced through infostealers.
Delivery methods have also become harder to spot. Attackers now use search engine poisoning, fake software installers, malicious browser extensions, and AI-crafted phishing emails. One emerging technique involves prompting users to paste a command into their terminal, it looks like a routine IT step and installs the stealer in seconds. Over 70% of infected devices in recent data were personal or unmanaged machines, which means the endpoint your business IT team never sees is often the starting point.
What you can do about it
You do not need a security operations centre to address this threat. A few practical changes make a real difference.
- Use a dedicated password manager instead of saving credentials in your browser. Browser-stored passwords are the primary target for most infostealers. A password manager keeps credentials in an encrypted vault that infostealers cannot reach as easily.
- Keep staff on company-managed devices wherever possible. Personal laptops are the biggest blind spot, no endpoint controls, no visibility, and saved work credentials sitting in the browser.
- Deploy endpoint detection and response (EDR) on all managed devices. Signature-based antivirus misses many modern infostealer variants. Behaviour-based EDR catches the exfiltration activity that signatures miss.
- Enable email security controls to filter phishing and malicious attachment delivery, still the most common infostealer entry point.
- Run regular IT security assessments to check which devices have unmanaged browser credential stores and where gaps in endpoint coverage exist.
- Train staff to recognise suspicious downloads, fake update prompts, and requests to paste commands into a terminal. The human layer matters more as delivery methods get more convincing.
- For Microsoft 365 environments, review session token lifetimes and consider Conditional Access policies that bind sessions to known, compliant devices.
What we see working for Brisbane SMEs
Across the businesses we support in South-East Queensland, the biggest gap we find is not the big-ticket security tools. It is browser credential hygiene and personal device use. A team of 20 people, each with saved passwords across personal browsers at home, is a much softer target than the same team using a managed password vault and company-issued devices, even before you add any other layer.
The second gap is visibility. Many SMEs have antivirus but no EDR. Antivirus checks files at the door. EDR watches what happens after something gets through. Infostealers are specifically designed to look normal until they are done. Behaviour-based detection is the practical answer, and it does not require enterprise budgets. Partners like Huntress make managed EDR accessible at SME scale.
The third gap is response speed. Knowing a credential has been stolen is only useful if you can act on it quickly. That means having a clear process for revoking sessions, rotating credentials, and checking for lateral movement, not working it out after the fact.
A quick check for your business
If you are not sure where you stand, these four questions are a useful starting point:
- Are any staff saving work passwords in a personal browser on a personal device?
- Do all company-managed endpoints have EDR, not just standard antivirus?
- Does your Microsoft 365 environment have Conditional Access policies in place?
- Do you have a process to revoke sessions and rotate credentials within hours if a breach is suspected?
If the answer to any of these is “no” or “not sure”, that is where to focus first. Our IT security assessments are a practical way to get a clear picture without having to work it out yourself.
Common questions about infostealers
Does MFA protect against infostealers?
Not on its own. MFA stops password-only attacks, but infostealers steal session cookies, the proof that you are already authenticated. An attacker with a valid session cookie bypasses the MFA step entirely. You also need session controls, short token lifetimes, and device-bound sessions to close that gap.
Are personal devices a real risk to business accounts?
Yes, and this is the most underestimated exposure for SMEs. Over 70% of infostealer infections in recent data hit personal devices. If a staff member has work credentials saved in a browser on their home laptop, those credentials are exposed, regardless of how secure your managed devices are.
How do infostealers spread?
The most common delivery paths are phishing emails, fake software installers, malicious browser extensions, and search engine results that lead to compromised download pages. A newer technique prompts users to paste a command into their terminal, disguised as a troubleshooting step. Essentially: anything that looks routine but installs software quietly.
What is the difference between antivirus and EDR for this threat?
Antivirus uses known file signatures to block recognised threats at the point of entry. EDR (endpoint detection and response) monitors behaviour continuously, it catches unusual activity like data being packaged and sent out, even if the malware itself has not been seen before. Most modern infostealer variants are designed to evade signature detection, which is why EDR matters for this threat class.
How quickly can stolen credentials be used against us?
Fast. Research shows credentials can move from an infected device to an underground marketplace to active use within hours. Some ransomware groups have deployed attacks within 48 hours of credentials appearing in stolen log sales. Speed of response, revoking sessions, resetting credentials, checking for lateral access, is as important as prevention.
Where should a small business start?
Start with browser credential hygiene: get staff off browser-saved passwords and onto a dedicated password manager. Then make sure every managed device has EDR, not just antivirus. These two steps address the most common infostealer entry and harvest points without requiring a large security budget or specialist staff.
How do we get started?
If you want a clearer picture of your current exposure, we can help. TTA works with businesses across Brisbane and South-East Queensland to identify gaps and put the right controls in place. Get in touch for a straightforward conversation about where to start.



