Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Anthropic Claude Services Down: claude.ai, Anthropic’s Code
June 6, 2026
Malicious Python Package Mimics Legitimate Parsimon
June 5, 2026
Hackers Weaponize Trusted Tools to Deploy Not Increasingly Weaponizing
June 5, 2026
Home/Threats/Cybercriminals Favor Infostealer Malware in Phishing Attacks
Threats

Cybercriminals Favor Infostealer Malware in Phishing Attacks

Phishing attacks consistently rank among the most prevalent methods cybercriminals employ to steal personal and business data. While the tactic itself isn’t new, a significant evolution has...

David kimber
David kimber
June 4, 2026 3 Min Read
7 0

Phishing attacks consistently rank among the most prevalent methods cybercriminals employ to steal personal and business data. While the tactic itself isn’t new, a significant evolution has emerged in the type of malicious software deployed. Threat actors are increasingly favoring infostealer malware as their primary payload, a trend extensively documented in recent analysis, including a detailed report from Malwarebytes.

Instead of tricking people into typing passwords on fake websites, attackers are now dropping malware directly onto victims’ devices to do the stealing for them.

This shift has been building gradually, and it signals a more dangerous phase in the evolution of online scams. Traditional phishing still exists and remains a serious threat.

However, a growing number of attackers now prefer to deploy infostealers, a category of malware designed to silently collect passwords, browser cookies, session tokens, saved autofill data, cryptocurrency wallet details, and even files stored on the device.

Analysts at Malwarebytes, in a report shared with Cyber Security News (CSN), noted that this approach is appealing because it scales well and reduces friction for the attacker.

Rather than waiting for a victim to visit a fake login page and enter credentials, the malware simply harvests whatever is already saved on the infected machine.

This also makes the attack much harder to spot. A classic phishing attempt often leaves visible red flags, a strange link, a suspicious sender address, or an oddly formatted login page.

Infostealers, by contrast, work quietly in the background after installation, giving victims little reason to suspect anything is wrong.

One significant driver behind this change is the widespread adoption of multi-factor authentication, or MFA. Because MFA adds an extra layer of login verification, stolen passwords alone are no longer enough for many account takeovers.

By stealing session cookies instead, attackers can bypass MFA entirely and access accounts without needing a password or a one-time code.

Cybercriminals Shift From Fake Login Pages

Another major factor is the explosion of the malware-as-a-service ecosystem, commonly known as MaaS. This underground market allows criminals to buy ready-made infostealer kits, loaders, and initial access tools without needing to build anything themselves.

It has dramatically lowered the bar for entry, letting even low-skilled attackers run large-scale credential theft campaigns. These services are not just cheap, they are also designed for speed and flexibility.

Operators can push out updates, rotate their infrastructure, and launch fresh campaigns quickly, while a network of affiliates handles distribution through phishing emails, fake downloads, malvertising, and social media traps.

The division of labor makes these operations highly efficient and difficult to shut down. Infostealers rarely mark the end of an attack, and in most cases, they are just the opening move.

The stolen data, including saved passwords, session cookies, and corporate access credentials, is packaged and sold to other criminals who specialize in account takeover, fraud, business email compromise, or ransomware deployment. A single infected device can generate income across multiple buyer types at once.

How Infostealers Reach Victims and How to Stay Safe

Infostealers reach victims through a wide range of delivery methods. Malicious ads, fake browser update prompts, pirated software, game cheats, cracked tools, and shady browser extensions are among the most common entry points.

These channels are effective because they reach people who are not necessarily expecting an attack and who may already be used to clicking through prompts without much thought.

A tactic called ClickFix has also gained traction recently. It works by tricking users into running commands or scripts on their own devices, often by presenting a fake error message or warning that instructs them to paste something into a command prompt.

Malwarebytes researchers warn that users should never execute any command copied from a website, email, or message unless they fully understand what it does and trust the source completely.

Staying safe requires building simple, consistent habits. Users should avoid clicking on sponsored ads and navigate directly to official websites when downloading software.

Pirated tools and cracked software carry a high risk of bundled malware and should be avoided entirely.

Slowing down before clicking any link or opening any attachment in an email can make a real difference, especially when the message creates a sense of urgency around billing, account issues, or security alerts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingransomwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader,

Next Post

CISA Warns: Critical Magento Cache Warmer R Exploited Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hola Browser Windows Pipeline Compromised to Deliver Cryptom
June 5, 2026
Microsoft 365 Bypass: Windows Driver Auto Service Degradation
June 5, 2026
Malicious Browser Add-Ons Target AI Users ChatGPT Claude
June 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us