This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Hackers, Threats & Vulnerability Management – Stealerlogs: The Doggy Door to your Organisation

Download resources

About this session

Vicky Desjardins, a PhD candidate in criminology at the University of Montreal and a cyber threat intelligence analyst, explains what infostealer malware, commonly traded as stealer logs, actually contains and how much damage it enables. She defines stealer logs as malware that harvests every saved credential, cookie, autofill entry, screenshot and social account from an infected device, sold as subscriptions or lifetime packages on criminal forums for roughly one hundred to a thousand US dollars. She walks through initial access brokers who resell these credentials to ransomware groups, drawing on her own ransomware research to note that a large share of strains rely on valid stolen accounts for lateral movement, not just initial entry. Beyond financial fraud and account hijacking, she details how the same data enables MFA bypass via email-based codes, extortion and sextortion built from browsing history, and physical stalking using calendar and appointment data. She closes with practical prevention advice: use MFA and EDR everywhere, never store passwords in browsers, refuse non-essential cookies, and treat personal and corporate device use as inseparable risks.

Key takeaways

  • Never store passwords in browser autofill; stealer malware harvests saved credentials, cookies and autofill data wholesale from infected devices.
  • Deploy MFA and EDR on every device, including personal ones, since stealer logs most often originate on unmanaged personal machines with no endpoint protection.
  • Treat MFA codes delivered by email as a weak link; if attackers already control the mailbox, they can intercept and delete the notification before you notice.
  • Do not reuse passwords between corporate and personal accounts; the two identities are functionally merged once either device is compromised.
  • Be as suspicious of links and files from known contacts as from strangers, since a breached colleague's or friend's account is a common vector for internal-looking phishing.

Speakers

Vicky Desjardins
Vicky Desjardins
Ph. D. candidate and Cyber Threat Intelligence Analyst · Hitachy Systems Security
Vicky Desjardins est une candidate au doctorat en criminologie à l'Université de Montréal, spécialisée dans le domaine complexe des méthodologies d'attaques par rançongiciels. Ses recherches doctorales portent sur des stratégies innovantes visant à… Read moreRead less

Vicky Desjardins est une candidate au doctorat en criminologie à l'Université de Montréal, spécialisée dans le domaine complexe des méthodologies d'attaques par rançongiciels. Ses recherches doctorales portent sur des stratégies innovantes visant à perturber de manière préventive les scripts d'attaque, contribuant ainsi de manière significative à l'évolution du paysage de la cybersécurité. Les activités académiques de Vicky comprennent une expertise en matière de priorisation des risques et d'analyse du comportement criminel, enrichie par son mémoire de maîtrise sur la priorisation des cas de sollicitation sexuelle en ligne présentant un potentiel élevé de contact hors ligne. Vicky dirige également la réponse aux cyberincidents, jouant un rôle crucial dans le confinement et la neutralisation des acteurs de la menace, ce qui souligne son expertise pratique dans le domaine.

Resources

Tags

More from GoSec 2023

Also from Vicky Desjardins

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.