There appears to be an uptick in interest among cybercriminals in infostealers – malware designed to swipe online account passwords, financial info, and other sensitive data from infected PCs – as a relatively cheap and easy way to get a foothold in organizations' IT environments to deploy devastating ransomware. Miscreants have plenty of ways to gain access to a business's internal systems. For example, they can brute-force their way in, logging into accounts with weak, default, or easily guessed passwords. They can buy their way in using so-called initial access brokers, who perform the actual infiltration. They can use credential stuffing, in which they obtain username-password combinations for one online service and see if those creds let them into another service as too many people reuse the same password everywhere. They could develop or obtain exploits for vulnerabilities in an org's IT estate, and use those to gain remote entry. Those methods can be tricky, expensive, a faff, or a dead end. An alternative and relatively straightforward way in would be to trick, say, an employee into running an infostealer on their work or home PC, and use credentials collected from that spyware to gain further access to an IT network. Infostealers tend to be used to gain access to victims' online bank accounts, remote desktop accounts, cryptocurrency wallets, email inboxes, and so on. It turns out, and logically it makes total sense, that these software nasties are good for getting ho...
Ransomware gangs are paying attention to infostealers, so why aren't you?
The Register
·Jessica Lyons
·Published Feb 29, 2024
·Updated
Affected Software
1 affected component
OpenAI Chatgpt
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the increasing interest of ransomware gangs in using infostealers to target sensitive data from infected PCs.
2
What security implications are discussed?
The rise in infostealer usage indicates a growing threat to online security and personal data for individuals and organizations.
3
What types of data are infostealers designed to collect?
Infostealers are designed to swipe online account passwords, financial information, and other sensitive data.
4
What groups are particularly interested in infostealers according to the article?
Ransomware gangs are notably paying more attention to the utilization of infostealers.
5
What is one affected software mentioned in the article?
ChatGPT from OpenAI is mentioned as an affected software in the context of security concerns related to infostealers.