Skip to content
  • Sign In
    Sign in

    Activate subscription >

    Add devices or upgrade >

    Renew subscription >

    Secure Hub >

    Don't have an account?
    Sign up >

    Sign In

  • Products

    < Products

    Solutions
    • Premium security antivirus
    • Privacy VPN
    • Identity Theft Protection
    • Personal Data Remover
    • Mobile security for iOS and Android
    • Looking for small business protection? Visit Teams
    Free device cleaners
    • Malware and virus remover
    • AdwCleaner
    • Antivirus trial
    Free identity and personal data scanners
    • Digital footprint scanner
    • Personal data scanner
    Free scam and ad blockers
    • Scam Guard
    • Scam number checker
    • Browser Guard
    See all free tools

  • Pricing
  • Partners
  • About
    Company
    • About Malwarebytes
    • Why Malwarebytes?
    • Jobs
    Newsroom
  • Resources

    < Resources

    Cybersecurity News
    • Malwarebytes Blog
    • Threat Center
    • Lock & Code podcast
    Cybersecurity Basics
    • What is Malware?
    • What is Antivirus?
    • What is Phishing?
    • See all topics
    Research reports
    • Modern Love in the Digital Age
    • Mobile Scam Report
    • How AI is reshaping trust, identity, and scams
    Small Business Learning Hub
    • Small business news
    • Upcoming Webinars
    See all resources
  • Help

    < Help

    Malwarebytes Help Center
    Community Forums
Free Download
  • Sign In
    Sign in

    Activate subscription >

    Add devices or upgrade >

    Renew subscription >

    Secure Hub >

    Don't have an account?
    Sign up >

    Sign In

Scams, Threat Intel

Infostealers are becoming the go-to phishing payload

by Pieter Arntz | June 3, 2026
phishing at scale
Add as a Preferred Source on Google

Phishing has changed. Slowly but surely, cybercriminals are turning to infostealers instead.

Traditional phishing hasn’t gone away. Far from it. But many attackers are no longer focused solely on tricking victims into entering usernames and passwords on fake login pages. Instead, they are using infostealers to quietly collect passwords, cookies, browser data, and other sensitive information from infected devices.

This approach is attractive because it scales well and reduces friction. Instead of relying on a victim to type credentials into a fake site, the malware can harvest logins already saved in browsers, session tokens, autofill data, cryptocurrency wallet details, and even files that contain useful information.

This makes the attack chain less visible. A traditional phishing email often leaves obvious clues: a suspicious link, a fake login page, or a strange attachment. Infostealers are different. They can arrive through malicious online ads (malvertising), cracked software, fake browser updates, game cheats, or dubious download sites, and once installed, they work in the background, stealing whatever the victim’s device has in store.

Part of this shift could be due to the widespread adoption of multi-factor authentication (MFA). By stealing session cookies, cybercriminals can bypass MFA, so they can access accounts without needing a password or authentication code.

Another factor is the rise of the malware-as-a-service (MaaS) ecosystem. Infostealers are cheap to deploy, easy to scale, and highly profitable. Rather than building a full attack chain themselves, many criminals buy access to ready-made stealer kits, loaders, or initial access services from underground vendors. This lowers the barrier to entry and allows less-skilled attackers to run credential theft operations.

In many cases, infostealers are just the first stage of a larger criminal operation. The stolen data is collected, packaged, and sold to other criminals interested in the harvested information. These buyers may specialize in fraud, account takeover, business email compromise, or ransomware. A single infected machine can generate multiple revenue streams: credentials for one buyer, session cookies for another, and corporate access or wallet data for a third.

That division of labor is one reason infostealers have become so persistent. Operators can update their code, rotate infrastructure, and launch new campaigns with minimal effort, while affiliates handle distribution through phishing, malvertising, fake downloads, or social media lures.

How to stay safe

Because infostealers commonly arrive through malvertising, fake browser updates, and one-click downloads, it’s worth treating ads and pop-ups with healthy skepticism. My personal tip: Never click on sponsored ads. Instead, visit official websites directly and download software only from trusted sources such as official vendor sites or app stores.

Another increasingly popular technique is ClickFix, a social engineering attack that tricks users into infecting their own devices. Never run commands or scripts copied from websites, emails, or messages unless you trust the source and understand the action’s purpose. If a website tells you to execute a command or perform a technical action, check official documentation or contact support before proceeding.


Picked up something you shouldn’t have?

RUN A FREE VIRUS SCAN


Pirated software, game cheats, and cracked tools remain some of the most common delivery methods for infostealers. These downloads often come bundled with malware that installs alongside the software you intended to get. The same caution applies to many browser extensions and add-ons that promise extra features or convenience. Stick to extensions from reputable developers, check reviews and permissions carefully, and avoid installing any add-on that asks for more access than it plausibly needs.

Phishing emails are still a major threat, but many can be spotted if you slow down and verify before clicking. Even if an email looks like it comes from a trusted brand, treat unsolicited attachments and links with caution, especially when they urge you to open a file, install something urgently, or fix a billing issue. If you’re unsure, check the sender address, look for typos or odd phrasing, and confirm the request through a separate channel such as the company’s official website rather than the link in the email.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

SHARE THIS ARTICLE

X
Add as a Preferred Source on Google

About the author

Pieter Arntz

Pieter Arntz Social icon

Malware Intelligence Researcher

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.

LATEST ARTICLES

News
Follow the clickfix instructions

Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts

July 3, 2026

Two new campaigns show how cybercriminals are increasingly relying on social engineering instead of software exploits to compromise devices and accounts.

Bugs
iPhone displaying Apple logo

Apple’s Hide My Email doesn’t hide it very well

July 2, 2026

A year ago a researcher found a vulnerability in Apple's Hide My Email feature and now he's tired of waiting for a fix.

Bugs
WinRAR logo

WinRAR flaw could allow attackers to take control of your computer

July 2, 2026

A new WinRAR update fixes a serious security flaw, but without automatic updates many users could miss the patch.

Add as a Preferred Source on Google

Related articles

  • Fake Google and Cloudflare verification pages spread multiple malware families

    Fake Google and Cloudflare verification pages spread multiple malware families

    July 2, 2026
  • Watch out for “high paying, low effort” Amazon job texts

    June 30, 2026
  • Beware of “Parcel Expert” job offers: They’re parcel mule scams

    June 25, 2026

Thank you for signing up!

Keep an eye on your email inbox for the latest newsletter

Sign up for our newsletter to get the latest cybersecurity news to your inbox

Sign Up

By submitting this form, you consent to Malwarebytes contacting you regarding products and services and using your personal data as described in our Terms of Service and Privacy Policy.

Contributors icon

Contributors

Threat Center icon

Threat Center

Podcasts icon

Podcast

Glossary icon

Glossary

Scams icon

Scams

Malwarebytes - all-in-one cybersecurity protection always by your side.

COMPUTER SECURITY

  • Rootkit Scanner
  • Trojan Scanner
  • Free Antivirus
  • Free Virus Scan
  • Premium protection

MOBILE SECURITY

google play store
  • iOS Security and Spam Blocker
apple store icon

PRIVACY PROTECTION

  • Digital Footprint Scan
  • Dark Web Monitoring
  • Adware Removal
  • Ad Blocker

IDENTITY PROTECTION

  • Identity Monitoring & Alerts
  • Credit Monitoring & Reporting
  • Identity Recovery & Resolution
  • ID Theft Insurance
  • Personal Data Remover
Threatdown powered by Malwarebytes logo
  • Business Endpoint Security Solutions
  • Managed Service Provider (MSP) Program

LEARN ABOUT CYBERSECURITY

  • Blog
  • Social Engineering
  • Phishing
  • Ransomware
  • Malware
  • Antivirus
  • What is a VPN?
  • Doxxing

PARTNER WITH MALWAREBYTES

  • Computer Repair
  • Affiliates
  • Strategic Business Partnerships
  • Resellers

ADDRESS

One Albert Quay
2nd Floor
Cork T12 X8N6
Ireland

2445 Augustine Drive
Suite 550
Santa Clara, CA
USA, 95054

ABOUT MALWAREBYTES

  • Careers
  • News and Press
  • Vulnerability Disclosure
  • Report a False Positive
  • Territory Notice
  • Special Offers

WHY US

  • Malwarebytes vs. Bitdefender
  • Malwarebytes vs. McAfee
  • Malwarebytes vs. Norton
  • Malwarebytes vs. Windows Defender

GET HELP

  • Forums
  • Sign in to MyAccount
  • Help Center
  • Twitter icon X
  • Icon facebook Facebook
  • Icon Linkedin LinkedIn
  • Icon youtube Youtube
  • Icon instagram Instagram
  • Reddit Social Icon Reddit

Cybersecurity info you can’t live without

Want to stay informed on the latest news in cybersecurity? Sign up for our newsletter and learn how to protect your computer from threats.

By submitting this form, you consent to Malwarebytes contacting you regarding products and services and using your personal data as described in our Terms of Service and Privacy Policy.

  • 日本語
  • Português Brasileiro
  • Deutsch
  • Español
  • Français
  • Italiano
  • Nederlands
  • Polski
  • Português
  • Русский
  • Your Privacy ChoicesCalifornia Consumer Privacy Act (CCPA) Opt-Out Icon
  • Legal
  • Privacy
  • Terms of Service
  • Accessibility

© 2026 All Rights Reserved