Close Menu
Voxa News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Mfpen Spring 2026 Menswear Collection

    June 26, 2025

    British and Irish Lions 2025: Sheehan to captain against Australian side Western Force

    June 26, 2025

    World’s oldest boomerang older than thought, but not Australian

    June 26, 2025
    Facebook X (Twitter) Instagram
    Voxa News
    Trending
    • Mfpen Spring 2026 Menswear Collection
    • British and Irish Lions 2025: Sheehan to captain against Australian side Western Force
    • World’s oldest boomerang older than thought, but not Australian
    • This Teen ‘Felt a Prick’ On a Fishing Trip Only to Discover a Rattlesnake Bite
    • Australia mushroom trial live: Erin Patterson jury to begin deliberations after judge’s charge concludes on Monday | Victoria
    • Surrey County Council announces fund for struggling households
    • US senators reintroduce bill to open Apple and Google’s app stores
    • The Bear season four review – finally becoming the show it was always destined to be | The Bear
    Thursday, June 26
    • Home
    • Business
    • Health
    • Lifestyle
    • Politics
    • Science
    • Sports
    • Travel
    • World
    • Entertainment
    • Technology
    Voxa News
    Home»Technology»Experts sound alarm on infostealer malware after login details exposed
    Technology

    Experts sound alarm on infostealer malware after login details exposed

    By Olivia CarterJune 26, 2025No Comments5 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Experts sound alarm on infostealer malware after login details exposed
    Share
    Facebook Twitter LinkedIn Pinterest Email


    “Someone, somewhere is having data exfiltrated from their machines as we speak,” says Volodymyr Diachenko, co-founder of the cybersecurity consultancy SecurityDiscovery.

    Sarayut Thaneerat | Moment | Getty Images

    Cybercriminals have intensified their efforts to steal and sell online passwords, experts warn. The alarm comes after the discovery of online datasets containing billions of exposed account credentials. 

    The 30 datasets comprised a whopping 16 billion login credentials across multiple platforms, including Apple, Google and Facebook, and were first reported by Cybernews researchers last week. 

    The exposures were identified over the course of this year by Volodymyr Diachenko, co-founder of the cybersecurity consultancy Security Discovery, and are suspected to be the work of multiple parties.

    “This is a collection of various data sets that appeared on my radar since the beginning of the year, but they all share a common structure of URLs, login details and passwords,” Diachenko told CNBC. 

    According to Daichenko, all signs point to the leaked login information being the work of “infostealers” — malware that extracts sensitive data from devices, including usernames and passwords, credit card information and online browser data. 

    While the lists of logins are likely to contain many duplicates as well as outdated and incorrect information, the overwhelming volume of findings puts into perspective how much sensitive data is circulating on the web. 

    It should also raise alarms on how infostealers have become the “cyber plague” of today, Daichenko said. “Someone, somewhere, is having data exfiltrated from their machines as we speak.”

    Daichenko was able to detect the exposed data because their owners had temporarily indexed them on the web without a password lock. Inadvertently shared data leaks are often caught by Security Discovery, but not at scales seen so far this year.

    Infostealer threats on the rise 

    According to Simon Green, president of Asia-Pacific and Japan at Palo Alto Networks, the sheer scale of the 16 billion exposed credentials is alarming and certainly notable, but not entirely surprising for those on the front lines of cybersecurity. 

    “Many modern infostealers are designed with advanced evasion techniques, allowing them to bypass traditional, signature-based security controls, making them harder to detect and stop,” he added.

    Consequently, there’s been an uptick in high-profile infostealer attacks. For example, in March, Microsoft Threat Intelligence disclosed a malicious campaign using infostealers that had affected nearly 1 million devices globally. 

    Infostealers typically gain access to victims’ devices by tricking them into downloading the malware, which can be hidden in everything from phishing emails to phony websites to search engine ads.

    The motive behind infostealer attacks is usually financial, with attackers often looking to directly take over bank accounts, credit cards, and cryptocurrency wallets or commit identity fraud. 

    Cybercriminals can use stolen credentials and other personal data for purposes such as crafting highly convincing, personalized phishing attacks and blackmailing individuals or organizations. 

    According to Palo Alto’s Green, the scale and dangers of those types of infostealers have intensified, thanks to the growing prevalence of underground markets that offer “cybercrime-as-a-Service,” in which vendors charge customers for malicious tools, sensitive data and other illicit online services.

    “Cyber crime-as-a-Service is the critical enabler here. It has fundamentally democratized cybercrime,” Green said.

    Those underground markets — often hosted on the dark web — create demand for cybercriminals to steal personal information and then sell that to scammers. 

    In that way, data breaches become about more than just the individual accounts — they represent a “vast, interconnected web of compromised identities” that can fuel subsequent attacks, Green said. 

    According to Diachenko, it’s likely that at least some of the compromised login datasets he identified had or will be traded to online scammers. 

    On top of that, malware kits and other resources that can help to facilitate infostealer attacks can be found on those markets. 

    CNBC has reported on how the availability of those tools and services has significantly lowered technical barriers for aspiring criminals, allowing sophisticated attacks to be executed at a massive, global scale. 

    The report found that infostealer attacks grew by 58% in 2024.

    What can be done

    With the increasing prevalence of malware and online usage, it’s now fair to assume that most people will, at some point, come in contact with an infostealer threat, said Ismael Valenzuela, vice president of threat research and intelligence at cybersecurity company Arctic Wolf.

    In addition to frequent password updates, individuals will need to be more alert about the increasing amount of malware hiding in illegitimate software, applications and other downloadable files, Valenzuela said. He added that the use of multi-factor authentication on accounts has become more important than ever.

    From a corporate perspective, it’s important to adopt a “zero trust architecture” that not only constantly authenticates the user, but also authenticates the device and user’s behavior, he added.  

    Governments have also been doing more to crack down on infostealing activities in recent months.

    In May, Europol’s European Cybercrime Centre said it had collaborated with Microsoft and global authorities to disrupt the “Lumma” infostealer, which it called “the world’s most significant infostealer threat.”

    alarm details experts exposed infostealer login malware sound
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Olivia Carter
    • Website

    Olivia Carter is a staff writer at Verda Post, covering human interest stories, lifestyle features, and community news. Her storytelling captures the voices and issues that shape everyday life.

    Related Posts

    US senators reintroduce bill to open Apple and Google’s app stores

    June 26, 2025

    Meta’s recruiting blitz claims three OpenAI researchers

    June 26, 2025

    ‘They’re Not Breathing’: Inside the Chaos of ICE Detention Center 911 Calls

    June 26, 2025

    Dan Rath: the 10 funniest things I have ever seen (on the internet) | Comedy

    June 26, 2025

    Tech Life

    June 26, 2025

    Aaron Sorkin is making a second ‘Social Network’ movie

    June 26, 2025
    Leave A Reply Cancel Reply

    Medium Rectangle Ad
    Top Posts

    UK government borrowing is second highest for May on record; retail sales slide – business live | Business

    June 20, 20252 Views

    Prosus bets on India to produce a $100 billion company, CEO says

    June 23, 20251 Views

    Support group helps Bristol woman with endometriosis

    June 21, 20251 Views
    Don't Miss

    This ruthless pursuit of disabled people has damaged Labour – no matter what happens next | Frances Ryan

    June 26, 2025

    One year ago, as cheering supporters waved union jacks to celebrate Labour’s election landslide, Keir…

    Mfpen Spring 2026 Menswear Collection

    June 26, 2025

    British and Irish Lions 2025: Sheehan to captain against Australian side Western Force

    June 26, 2025

    World’s oldest boomerang older than thought, but not Australian

    June 26, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Medium Rectangle Ad
    Most Popular

    UK government borrowing is second highest for May on record; retail sales slide – business live | Business

    June 20, 20252 Views

    Prosus bets on India to produce a $100 billion company, CEO says

    June 23, 20251 Views

    Support group helps Bristol woman with endometriosis

    June 21, 20251 Views
    Our Picks

    36 Hours on the Outer Banks, N.C.: Things to Do and See

    June 19, 2025

    A local’s guide to the best eats in Turin | Turin holidays

    June 19, 2025

    Have bans and fees curbed shoreline litter?

    June 19, 2025
    Recent Posts
    • This ruthless pursuit of disabled people has damaged Labour – no matter what happens next | Frances Ryan
    • Mfpen Spring 2026 Menswear Collection
    • British and Irish Lions 2025: Sheehan to captain against Australian side Western Force
    • World’s oldest boomerang older than thought, but not Australian
    • This Teen ‘Felt a Prick’ On a Fishing Trip Only to Discover a Rattlesnake Bite
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    2025 Voxa News. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.