Learn

What is an "infostealer" — and why a strong password may not be enough

Most advice about staying safe online is about your password: make it long, do not reuse it, turn on two-factor. That is all still good. But a kind of malware called an "infostealer" gets around all of it — by quietly copying what is already saved on your device. It is a big part of why you keep seeing "billions of passwords leaked" headlines. Here is what it actually does, and the few simple habits that stop it.

Check a password privately

Key takeaways

  • An infostealer is malware that copies saved data straight off your device: browser-saved passwords, autofill details, and your active login "cookies".
  • Those stolen cookies are the dangerous part — they can let an attacker into an account without your password and without your two-factor code.
  • It usually sneaks in through pirated or "cracked" software, fake "free" downloads, and dodgy email attachments — not by guessing your password.
  • The giant "billions of passwords leaked" headlines are mostly piles of this stolen data, collected and resold — not always one fresh hack.
  • A few habits cut the risk a lot: do not install software from random sites, keep your device updated, use a real password manager instead of your browser, and turn on passkeys where you can.

What an infostealer actually steals

An infostealer is a small program that, once it runs on your computer or phone, quietly copies the useful things sitting on it and sends them to whoever is behind it. Top of the list are the passwords your web browser has saved for you, along with the addresses, card details and other autofill it keeps handy. It does not need to break any encryption to do this — it simply reads what is already unlocked while you are using the device.

The part people miss is that it also grabs your "cookies" — the small login tokens a website leaves on your device so you do not have to sign in every single time. It can also scoop up things like cryptocurrency wallet files and the logged-in sessions of chat apps. All of this gets bundled into what criminals call a "stealer log" and sold or traded.

Why it gets past a strong password

A long, unique password is great protection against someone guessing their way in. But an infostealer does not guess — it copies. If your browser already knows the password, the malware just takes the saved copy. Length and complexity do not slow that down at all.

The stolen login cookie is what makes this really slip past your defences. That cookie is proof to the website that you already signed in successfully. Hand a copy to an attacker and, for as long as it is valid, they can often walk straight into the account without the password screen and without being asked for your two-factor code — because the site thinks the sign-in already happened. That is why "I have two-factor on" is not, by itself, an answer to this threat.

How it ends up on your device

Infostealers almost always need you to run something. The common routes are pirated or "cracked" paid software, fake "free download" and demo pages that copy a real product, a booby-trapped email attachment, or a misleading advert that leads to a fake installer. There is nothing exotic here — no unstoppable hack, just a file that looks safe and is not. The single most useful habit is to install software only from the maker or an official app store.

What to do if you think you are affected

If you have any reason to think something got onto your device, work in this order — the order matters, because fixing passwords while the malware is still watching just hands it the new ones too.

1. Clean the device first. Run a reputable security scan, or if in doubt get help removing the malware, before you change anything. Until the device is clean, treat it as if someone is reading over your shoulder.

2. Reset passwords from a device you trust. Starting with your email and anything that can reset other accounts, change passwords from a different, clean device. Make each new one unique — a password manager makes this easy.

3. Sign out everywhere, then add stronger locks. Use each service's "log out of all devices" option to cancel any stolen cookies, then turn on two-factor and a passkey where offered.

How to lower your risk from now on

You do not need to live in fear to avoid this. Install software only from the maker or an official store, and skip "cracked" or pirated apps entirely. Move the passwords out of your browser and into a dedicated password manager, then let the browser forget them. Keep your device and browser updated so known holes are closed. And turn on passkeys wherever you can — a passkey leaves nothing saved for a stealer to copy, and it cannot be phished the way a password can.

The honest limits — and where Sealby fits

Here is the straight version: no single app, Sealby included, can fully protect a device that is already infected. If malware is running with the run of your machine, good habits and clean-up matter more than any one tool. This is about the health of the device in your hand first.

What Sealby does is keep the things you choose to protect — your private photos, videos, notes and files — encrypted on your own device, with a key only you hold, instead of sitting in easy reach. And our free password leak check lets you test a password privately, without sending it anywhere. The lesson of infostealers is the same one Sealby is built on: keep what matters actually locked, not lying around.

This is general education, not security advice. Threats, tools and app features change over time and differ by device — check current, reputable sources and the settings on your own device.

Quick answers

If I have a strong, unique password, am I safe from this?

It helps, but not completely. An infostealer copies the password you have already saved and your active login cookie, so it can get into an account without cracking anything. The strongest extra protections against this are passkeys and signing out of old sessions ("log out everywhere").

How would I know if I have been hit?

Often you cannot tell directly, because the malware is designed to be quiet. Warning signs are logins or purchases you did not make, or a security tool flagging something. If you ever installed something you were unsure about, it is safest to treat your saved passwords as exposed: clean the device first, then reset your passwords from a device you trust.

Does turning on two-factor stop infostealers?

Two-factor still helps against ordinary password theft, so keep it on. But a stolen "session cookie" can skip a normal two-factor prompt, because to the website it looks like you are already signed in. Passkeys and signing out of all devices are stronger answers to this particular threat.

Your vault is waiting.

Download Sealby and protect what matters. Setup takes under a minute, and there’s no account to create.

Download on the App Store

iPhone & iPad · iOS 17+ · Free