Au-delà du maliciel de type infostealer : vecteurs d’infection, les actifs dérobés inusités et les contre-mesures
Download resourcesAbout this session
Olivier Bilodeau (MontréHack, NorthSec) and Mathieu Lavoie (Flare) unpack the infostealer economy behind data breaches, using their own coinage 'klepto-logiciel' throughout. They trace the typical infection chain, a cracked-software search leading to a bloated installer via a hijacked YouTube account or a malicious Google Ad, and show that stealers run entirely in the user's context, needing no admin rights or persistence, which makes them hard to catch in incident response. Stolen data is aggregated and resold on Telegram channels and dedicated marketplaces, feeding initial access brokers and, per leaked chat logs, top-performing ransomware affiliates. A new screenshot feature, now in 15-20% of stealers, lets them reconstruct real infection stories, including a Midjourney-themed ad campaign that talks victims into disabling their antivirus. Olivier's own research shows stealers can also extract TOTP seeds from a Chrome extension, crack KeePass vaults offline, and reconstruct valid Google session cookies from Chromium's own code, though standalone managers like Bitwarden resist extraction. They close on Chrome's bypassed-but-still-useful app-bound encryption defense, credential-testing scripts, and recent law enforcement takedowns (Genesis Market, Operation Magnus against Redline) with mixed, still-unfolding results.
Key takeaways
- Treat infostealer infection as a real risk even without admin rights or persistence: stealers run entirely in the user context, exfiltrate once and exit, and are hard to catch in incident response.
- Never let staff disable antivirus 'to make an installer work'; that social-engineering step is a core part of most infostealer infection chains, not an edge case.
- Move IT staff to a standalone password manager instead of the browser's built-in one; researchers found no confirmed infostealer extraction technique against products like Bitwarden.
- Regularly check your organization's domains against a threat-exposure or stealer-log vendor; roughly one breach in three now traces back to compromised credentials, and shadow IT (non-SSO SaaS signed up with a corporate email) often surfaces this way.
- Proactively test breached credentials and reset accounts fast, since even MFA can be bypassed by a single misconfigured service; ad-blocking and Windows SmartScreen also measurably cut the largest infection vector, malicious search ads.
Speakers

Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur… Read moreRead less
Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur passionné, Olivier a présenté lors de conférences telles que AtlSecCon, BlackHat, DEFCON, SecTor, Derbycon, et bien d’autres. Très impliqué dans sa communauté, il coorganise MontréHack, est président de NorthSec, et anime son Hacker Jeopardy.

Mathieu Lavoie est cofondateur et CTO de Flare. Après avoir été chercheur en logiciels malveillants pendant quelques années, il a travaillé comme testeur d'intrusion puis comme chef d'équipe de sécurité dans une grande institution financière. Il a… Read moreRead less
Mathieu Lavoie est cofondateur et CTO de Flare. Après avoir été chercheur en logiciels malveillants pendant quelques années, il a travaillé comme testeur d'intrusion puis comme chef d'équipe de sécurité dans une grande institution financière. Il a également été conseiller stratégique auprès de cadres supérieurs concernant la cybersécurité et les initiatives blockchain. Il a présenté ses travaux lors de conférences sur la cybersécurité telles que HOPE, BotConf, Sleuthcon et NorthSec.


