Join our Newsletter — 33% off our NHI Course
Threats, Abuse & Incident Response

Password Stealer

← Back to Glossary
By NHI Mgmt Group Updated September 26, 2026 Domain: Threats, Abuse & Incident Response

A password stealer is malware designed to harvest credentials and related data from browsers, applications, and local system files. It typically collects passwords, cookies, form autofill entries, and session information, then sends the results to an operator for reuse, resale, or follow-on compromise.

What Password Stealers Do

Password stealers are designed to quietly collect reusable access material from endpoints, then exfiltrate it for reuse or resale. Their value comes from harvesting not just passwords, but also cookies, autofill data, and session artefacts that can shortcut normal authentication checks.

Because the malware targets local browser stores, application caches, and user profile data, it can capture credentials that users never explicitly type into a login form. That makes the compromise broader than a single account password and more useful to attackers who want immediate access.

How Password Stealers Work

Most password stealers focus on stealing data already present on the victim system. They may search browser vaults, memory, local files, and other storage locations where credentials or session tokens are kept, then package the results and send them to command infrastructure.

The operator often does not need to exploit the target application directly once the steal has occurred. A stolen cookie or session token can bypass a fresh login entirely, which is why these malware families are so effective against accounts protected only by passwords.

Many stealers are built for scale rather than precision. They are deployed to collect credentials from many endpoints, especially where users reuse passwords across services or where browser-saved secrets remain accessible to local malware.

Why Stolen Credentials Are So Valuable

Credentials taken by password stealers are usually monetised quickly. They can be used for account takeover, sold in criminal markets, or chained into phishing, business email compromise, fraud, and further intrusion activity.

The most damaging cases are often not the password itself, but the related session material. If a stealer captures authenticated browser state, attackers may inherit an already-open session and avoid MFA prompts, password resets, or other standard access barriers.

This is also why password stealers are frequently part of a larger compromise chain. Initial access may come from a fake download, malicious attachment, or trojanised installer, but the real objective is often credential harvesting and subsequent reuse against cloud services, SaaS portals, and internal systems.

What Defenders Need to Understand

Password stealers change the defensive question from “Was the password strong?” to “Can local malware reach the secrets and sessions that the browser or application stores?” Protection depends on limiting secret exposure on endpoints, reducing credential reuse, and treating session theft as a real takeover path.

Visibility matters as much as prevention. Sudden credential reuse from unfamiliar locations, abnormal browser profile access, or unexpected outbound exfiltration from endpoints can all indicate steal-and-reuse activity rather than ordinary user behaviour.

Defence is strongest when authentication, endpoint protection, and token handling are designed together. If secrets remain broadly available on a device, malware only needs one successful read to turn a local compromise into wider account compromise.

Risk and Threat Considerations

Password stealers create direct account-takeover risk because they are built to harvest the exact material that protects user sessions. The threat is amplified when cookies or session tokens are stolen alongside passwords, since attackers can reuse authenticated state without re-entering credentials.

Failure mechanism: Malware gains local access to browser stores, caches, or profile data, then exfiltrates passwords, tokens, and session artefacts before the victim notices.

Impact: Attackers can pivot from one infected endpoint to mailbox, SaaS, or enterprise account compromise, then use those accounts for fraud, espionage, or further intrusion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPassword stealers target credentials and session material managed under authenticator lifecycle controls.
IA-2 — Identification and Authentication (Organizational Users)Credential theft undermines organizational user authentication and enables account takeover.
AC-6 — Least PrivilegeLimiting user and process privilege reduces what malware can harvest and reuse after compromise.
Recommendation — Restrict authenticator storage and rotate any credentials exposed to malware. Strengthen user authentication to reduce the value of stolen passwords. Enforce least privilege to constrain the blast radius of stolen credentials.
MITRE ATT&CKT1555 — Credentials from Password StoresPassword stealers specifically harvest passwords and related secrets from local stores.
T1552 — Unsecured CredentialsThe technique covers theft of secrets exposed in files, caches, and application data.
Recommendation — Hunt for credential theft activity in browser and vault stores. Find and eliminate exposed secrets in local files and application storage.

Practitioner Guidance

What to watch for: Treat password stealer risk as an endpoint-plus-identity problem. If users can sign in from a compromised device, saved credentials and session material may be enough to bypass intended access controls even when the original password never leaves the endpoint.

Practitioner takeaway: The critical control question is not only whether a password is strong, but whether the device ever exposes reusable secrets or long-lived sessions to local malware.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org