Overview
Stealers such as RedLine, Raccoon and Vidar are sold as a service and shipped inside fake updates or pirated software.\nThe real prize is often session cookies rather than passwords, because a stolen cookie replays a login that is already past MFA.\nOutput is uploaded as a small archive within minutes of infection.
Indicators of Compromise
Signals that suggest this is present on a system.
- Browser profile directories read by an unknown process
- ARCHIVE files staged in temp folders
- Valid logins from new devices shortly after a download