Infostealer malware compromises gaming and high-value organization accounts worldwide

A Data-Driven Analysis of Infostealer Malware Victims

Cryptography and Security

Summary

Infostealer malware steals sensitive information like passwords and private keys from infected devices. The authors created a safe way to study these stolen data records without exposing sensitive details. They analyzed over 170,000 victims and found that popular services, especially gaming and entertainment platforms, are heavily targeted. They also uncovered compromised credentials from important organizations like government, law enforcement, and major universities. The study highlights risks from reusing passwords and overlap with other cyber threats like phishing and ransomware.

What this means in practice

  • For information security teams: Identify real-world victim profiles and prioritize protection for heavily targeted services and organizations using anonymized malware victim data.
  • For cyber threat intelligence analysts: Use the released anonymized victim dataset for developing better threat models linking infostealer activity to phishing and ransomware attacks.

Authors

Arttu Paju, Juha Nurmi, David Arroyo, Sergio Chica Manjarrez, Fran Casino, Mikko Niemelä, Juuso Itkonen, Joel Scanlan, Constantinos Patsakis, Georgios Smaragdakis

Abstract

Infostealer malware infects devices worldwide and harvests their most sensitive contents: credentials, browser sessions, private keys, and access certificates. Yet its impact on victims remains difficult to study without an ethical, legal, and curated research dataset. To close this gap, we build a privacy-preserving pipeline that turns illicitly sourced infostealer logs into a reproducible research artifact, minimizing sensitive data while preserving measurement utility, and use it to construct a dataset of 170,298 victims from logs of multiple infostealer families. Analyzing these victims, we find that the most compromised services mirror the world's most popular platforms, with gaming and entertainment services strongly overrepresented. Within the sample we identify compromised credentials for high-value organizations, including law-enforcement domains, government and military services, and all eight Ivy League universities, as well as substantial exposure of security-critical infrastructure and of financial, remote-access, and development platforms. Victims also show widespread credential reuse and significant revictimization risk, overlapping with phishing and ransomware victim populations. We release the first anonymized victim-level infostealer dataset under controlled access to enable ethical, privacy-preserving, and reproducible research on information security and victim behavior.