How Hackers Use Malicious Attachments (Infostealers) to Steal Your Data

Session cookies are what infostealers are really after, because replaying one skips the login prompt altogether. MFA doesn't fail against this , it's never asked.

Share
How Hackers Use Malicious Attachments (Infostealers) to Steal Your Data
Photo by Kasia Derenda / Unsplash

Infostealers have quietly become the most valuable commodity in the cybercrime economy. They aren't ransomware, they don't encrypt anything, and they rarely make headlines, but stolen credentials and sessions are now the leading way attackers get into both consumer accounts and enterprise networks.

The numbers make the point. Flashpoint's midyear threat report counts roughly 1.7 billion credentials harvested in the first half of 2026, pulled from 7.4 million infected devices, up 27% on the previous six months. Vidar, StealC and Lumma did most of the work. Cisco Talos's Q1 2026 incident response data shows phishing back on top for initial access, with exploitation of public-facing applications falling from 62% of engagements to 18% and valid accounts accounting for a quarter, and the credentials in question are overwhelmingly stealer-log-derived.

This piece is about how that works, and why the usual advice about "don't open attachments" misses most of it.

What an infostealer actually takes

An infostealer is malware that runs for a few seconds and leaves. It doesn't encrypt your files or demand payment. It looks for:

  • Saved passwords from browsers and password managers
  • Session cookies, and this is the part that matters most
  • Autofill data: names, addresses, card numbers
  • Crypto wallet files and browser extensions
  • System information for fingerprinting

The session cookie is the prize, and understanding why explains everything else about this threat.

When you log in to Gmail, Microsoft 365 or your bank, the server hands your browser a small file (a session cookie) that says this person is already authenticated. That's how you stay logged in between visits. You don't re-enter your password every time you check your mail, and you don't re-answer an MFA prompt either.

An infostealer copies that cookie. The attacker loads it into their own browser and the server serves them your account, because the cookie is valid and recently issued.

MFA doesn't fail in this scenario. It is never asked. The factor was satisfied at the moment the session was created, before the theft. A one-time code or a push notification offers no protection against a session that's already authenticated, which is why the standard "enable 2FA and you're fine" advice is incomplete.

In practice, stolen credentials are often the lesser half of the haul. Flare analysed 18.7 million infostealer logs from 2025 and found 1.17 million contained both credentials and live session cookies for the same account, enough for immediate access that skips authentication entirely.

How it actually reaches you in 2026

The distribution playbook has shifted away from malicious email attachments. It's built on social engineering rather than exploits, and the delivery methods worth knowing are these:

Fake CAPTCHA (ClickFix). A page claims it needs to verify you're human, then instructs you to press Win+R, paste a string from your clipboard and hit Enter. The string is a PowerShell command. You compromise your own machine, by hand, which neatly sidesteps most download-based defences. This is the technique behind the CastleLoader-to-Lumma chain Bitdefender documented in early 2026, and it's the fastest-growing delivery method.

SEO poisoning and fake installers. Search for a popular tool and a poisoned result offers you an installer. EXE downloads and DLL side-loading are the primary execution vectors here, and this remains the dominant delivery method overall. Fake "your browser is out of date" pages push installers signed with stolen or short-lived certificates, so they look legitimate.

Pirated software and game launchers. Cracked apps and trainers are a reliable infection route, and an increasingly aggressive one on macOS, where pirated software is scarcer and users are less primed to expect it.

Fake troubleshooting advice. ClickFix campaigns host fake macOS troubleshooting posts (for example a page styling itself as a guide to freeing up disk space) instructing readers to paste a command into Terminal to "fix" the problem. The command decodes and runs a loader. Microsoft's security blog documented this evolution, including a later variant that used a cluster of look-alike domains and a browser-fingerprinting gate so the lure was served mainly to visitors whose environment looked like a genuine Mac.

macOS is not exempt. Atomic Stealer (AMOS) is a macOS specialist distributed through malicious .dmg files and pirated Mac apps. Microsoft issued a Mac-specific warning in February 2026, naming AMOS alongside MacSync and DigitStealer for campaigns running since late 2025.

The old pattern (a Word document with a macro, or a ZIP that "failed to open") still exists. It's just no longer the main event, and a post that only prepares you for attachments leaves you exposed to the routes above.

Where the stolen data goes

Stealer logs are traded at industrial scale, and Flare puts more than 90% of the logs it sees on Telegram. Telegram channels and dedicated marketplaces sell fresh logs with a searchable interface: buyers filter by domain, by country, or by the presence of a specific cookie. Genesis Market normalised this model, advertising access to data from over 1.5 million compromised computers, before it was seized in April 2023 under Operation Cookie Monster; Russian Market and its successors carried on.

For enterprise intrusions, the log market is the supply chain. Rather than breaking into a network, an attacker buys a log containing valid credentials and a live session cookie for a VPN gateway or cloud console, replays the session, and is inside, no exploit, no phishing campaign, no initial foothold to establish. That's why credential-based access has displaced exploits as the leading way in.

What actually reduces your risk

Protect the keystone account first. Your email account can reset almost everything else you own. If you secure one account properly, make it that one, ideally with a hardware key rather than an app code.

Use passkeys or FIDO2 keys on your most important accounts. These don't fix session theft, but they close the credential-theft path, and they can't be relayed by real-time phishing kits the way TOTP codes can. How to set up a YubiKey covers the registration steps.

Get your passwords unique and stop typing them. A password manager means one compromise doesn't cascade, and it means you aren't entering credentials into pages you reached from a link. Why using a password manager matters covers the reasoning; the password manager comparison covers which one.

Treat "paste this command" as a red flag, always. No legitimate website, support agent or troubleshooting guide needs you to paste a command into PowerShell or Terminal to prove you're human or to fix a browser error. This single rule defeats ClickFix entirely.

Log out of sensitive accounts when you're done. It invalidates the session cookie, so a stealer that runs afterwards gets a token that no longer works. Inconvenient, which is why almost nobody does it, but it's the direct countermeasure to pass-the-cookie.

Don't disable your security software, whatever the page claims about false positives or a required update.

Patch, and be careful what you install. Outdated browsers and plugins are still scanned for. Pirated software and cracked installers are a delivery route by design, not by accident. Avoid installing apps from unknown sources covers the habit.

Keep an offline backup. Infostealers themselves don't encrypt your files, but they're frequently the first stage before something that does.

For organisations: this is the part most security programmes are still behind on. Bind sessions to device posture where your identity provider supports it, so a cookie replayed from an unrecognised device fails. Shorten session lifetimes for privileged access. Alert on impossible-travel and new-device logins for your cloud consoles and VPN gateways, because those are what the logs are bought for. And monitor for your own domain's credentials appearing in log marketplaces, if your users' sessions are being sold, you want to know before someone uses one.

The short version

Infostealers run briefly, steal saved credentials and session cookies, and sell them. The session cookie is the valuable part because replaying it skips the login prompt. MFA isn't defeated, it's simply never triggered. The delivery has moved from email attachments to fake CAPTCHAs, poisoned search results and fake installers, and macOS is a growing target.

The highest-value defences are a hardware key on your email account, never pasting commands you were told to paste, and for organisations, binding sessions to devices so a stolen cookie doesn't work from somewhere else.

If you're worried about where your data lives more generally, cloud storage and privacy covers the trade-offs, and if you've just clicked something suspicious, what to do after clicking a phishing link walks through the response in order.

## Convertkit Newsletter