🤖 AI Summary
This study addresses the challenge of quantifying the real-world harm caused by information-stealing malware, which has been hindered by the absence of ethically compliant datasets. To overcome this limitation, we propose a privacy-preserving pipeline that processes illicit logs by integrating data anonymization with multi-source aggregation techniques. This approach yields the first controlled-access, anonymized victim-level dataset comprising 170,000 victims, effectively balancing data utility with privacy protection. Our analysis reveals elevated data leakage rates on gaming and entertainment platforms, alongside significant exposure risks for high-value targets such as government agencies and academic institutions. Furthermore, the findings empirically confirm the prevalence of credential reuse and repeated victimization. Ultimately, this work establishes a robust empirical foundation for comprehensive threat assessment within the cybersecurity landscape.
📝 Abstract
Infostealer malware infects devices worldwide and harvests their most sensitive contents: credentials, browser sessions, private keys, and access certificates. Yet its impact on victims remains difficult to study without an ethical, legal, and curated research dataset. To close this gap, we build a privacy-preserving pipeline that turns illicitly sourced infostealer logs into a reproducible research artifact, minimizing sensitive data while preserving measurement utility, and use it to construct a dataset of 170,298 victims from logs of multiple infostealer families. Analyzing these victims, we find that the most compromised services mirror the world's most popular platforms, with gaming and entertainment services strongly overrepresented. Within the sample we identify compromised credentials for high-value organizations, including law-enforcement domains, government and military services, and all eight Ivy League universities, as well as substantial exposure of security-critical infrastructure and of financial, remote-access, and development platforms. Victims also show widespread credential reuse and significant revictimization risk, overlapping with phishing and ransomware victim populations. We release the first anonymized victim-level infostealer dataset under controlled access to enable ethical, privacy-preserving, and reproducible research on information security and victim behavior.