It appears that ransomware groups are showing increased interest in infostealers – malware designed to steal online account passwords, financial information, and other sensitive data from infected computers – as a relatively cheap and easy way to gain access to organizations’ IT environments to implement their destructive ransomware.
See also: Ukrainian administrator of Raccoon Infostealer Malware arrested

Criminals have many ways to gain access to an organization’s internal systems. For example, they can brute force their way into accounts with weak, default, or easily guessed passwords. They can buy their way in, using so-called initial access intermediaries, who perform the actual intrusion. They can use the technique of credential stuffing, in which they obtain username-password combinations for one online service and check whether those credentials allow them to log in to another service, since many users reuse the same password across all of them. They could develop or obtain exploits for vulnerabilities in an organization’s IT environment and use them to gain remote access.
These methods can be difficult, expensive, inconvenient, or dead-end. An alternative and relatively simpler way for ransomware groups would be to trick, for example, an employee into running infostealers on computer at work or at home, and use the credentials collected by this malware to gain further access to an IT network. Infostealers are typically used to gain access to victims' online banking accounts, remote desktop accounts, cryptocurrency wallets, emails, and more.
See also: Infostealer malware: Why do cybercriminals prefer it?

Although ransomware gangs and other criminal groups are wary, according to security researchers, companies are still not paying due attention to infostealers.
According to the data provided, Kaspersky reported that more than 36 million credentials were stolen by infostealers between 2021 and 2023. OpenAI, in particular, had an explosion in user credentials being removed from users' PCs due to infostealers during this period.
Around 688,000 credentials for the hyper-lab’s services, including ChatGPT, were acquired between 2021 and 2023 and sold on dark web, according to the Russian infosec house. Almost all of these (663,719) appeared for sale on dark web marketplaces last year alone, representing an increase of over 3,161% compared to 2022.
See also: Infostealer malware is a precursor to ransomware attacks
What are the best methods of protection against infostealers?
One of the best ways to protect yourself from infostealers used by ransomware groups is to use strong, unique passwords. This can prevent attackers from accessing your digital assets. Keeping your software and applications up to date is another important way to protect yourself. Using antimalware software and a firewall can also provide additional protection. These tools can detect and remove infostealers before they can do any damage. Finally, information security education is crucial. Understanding how infostealers operate and the tactics they use can help you avoid attacks.
Source: theregister
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
