Uploaded December 2025 | Updated September 2026, 2 weeks ago
Beyond the Malware: Dissecting Information Stealers' Infection Vectors, Stolen Assets and Countermeasures
Speakers: Olivier Bilodeau and Eric Boivin, Senior Technical Platform Specialist Flare
Modern information stealers have grown far beyond basic credential theft and now operate as highly advanced tools capable of capturing full digital fingerprints of their victims. In this technical deep dive, the speaker presents new research into how modern stealers are built, how their attack chains operate, and where defenders still have opportunities to detect and disrupt them.
Using real-world compromise scenarios, including desktop screenshots captured at the moment of infection, this session breaks down how threat actors achieve large-scale deployment through compromised advertising networks and trojanized software. The talk draws directly from hands-on stealer log analysis to show how these threats bypass multi-factor authentication, interact with password managers, and extract cryptocurrency wallets.
You’ll also learn how Chrome’s application-bound encryption works, why it has already been circumvented, and how it still introduces new detection opportunities for defenders. The session wraps up with practical defensive guidance and the release of two community resources, including a PowerShell script for automated credential testing against Entra ID and a curated dataset of stealer logs for security research.
This presentation gives security practitioners concrete insights and tools to better defend against one of today’s most impactful and underexamined threats.
Chapters:
00:00 Welcome & Agenda
01:24 What Are Information Stealers?
02:18 How They Work & What They Steal
04:46 Inside a Stealer Log
06:36 Malware-as-a-Service Economy
07:37 Stealer Families & Features
09:48 Distribution & Log Marketplaces
12:29 Scale of the Problem
14:29 Real-World Impact & Breach Data
15:25 Case Study: MidJourney Campaign
18:19 Infection Vectors & Trends
19:06 Beyond Credentials: Files & MFA
22:09 Password Managers & Session Hijacking
26:03 Chrome’s Application-Bound Encryption
29:18 Defensive Strategies & Credential Validation
31:48 Law Enforcement Actions & Takedowns
33:48 Key Takeaways & Community Resources
Sign Up for WWHF
wildwesthackinfest.com/register
#cybersecurity #infosec #threatresearch #malwareanalysis #blueteam #securityresearch #digitalforensics #wwhf #wwhf2026
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
Beyond the Malware: Dissecting Information Stealers' Infection Vectors, Stolen Assets and Countermeasures
Speakers: Olivier Bilodeau and Eric Boivin, Senior Technical Platform Specialist Flare
Modern information stealers have grown far beyond basic credential theft and now operate as highly advanced tools capable of capturing full digital fingerprints of their victims. In this technical deep dive, the speaker presents new research into how modern stealers are built, how their attack chains operate, and where defenders still have opportunities to detect and disrupt them.
Using real-world compromise scenarios, including desktop screenshots captured at the moment of infection, this session breaks down how threat actors achieve large-scale deployment through compromised advertising networks and trojanized software. The talk draws directly from hands-on stealer log analysis to show how these threats bypass multi-factor authentication, interact with password managers, and extract cryptocurrency wallets.
You’ll also learn how Chrome’s application-bound encryption works, why it has already been circumvented, and how it still introduces new detection opportunities for defenders. The session wraps up with practical defensive guidance and the release of two community resources, including a PowerShell script for automated credential testing against Entra ID and a curated dataset of stealer logs for security research.
This presentation gives security practitioners concrete insights and tools to better defend against one of today’s most impactful and underexamined threats.
Chapters:
00:00 Welcome & Agenda
01:24 What Are Information Stealers?
02:18 How They Work & What They Steal
04:46 Inside a Stealer Log
06:36 Malware-as-a-Service Economy
07:37 Stealer Families & Features
09:48 Distribution & Log Marketplaces
12:29 Scale of the Problem
14:29 Real-World Impact & Breach Data
15:25 Case Study: MidJourney Campaign
18:19 Infection Vectors & Trends
19:06 Beyond Credentials: Files & MFA
22:09 Password Managers & Session Hijacking
26:03 Chrome’s Application-Bound Encryption
29:18 Defensive Strategies & Credential Validation
31:48 Law Enforcement Actions & Takedowns
33:48 Key Takeaways & Community Resources
Sign Up for WWHF
wildwesthackinfest.com/register
#cybersecurity #infosec #threatresearch #malwareanalysis #blueteam #securityresearch #digitalforensics #wwhf #wwhf2026
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com










