A Data-Driven Analysis of Infostealer Malware Victims

📅 2026-09-24
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge of quantifying the real-world harm caused by information-stealing malware, which has been hindered by the absence of ethically compliant datasets. To overcome this limitation, we propose a privacy-preserving pipeline that processes illicit logs by integrating data anonymization with multi-source aggregation techniques. This approach yields the first controlled-access, anonymized victim-level dataset comprising 170,000 victims, effectively balancing data utility with privacy protection. Our analysis reveals elevated data leakage rates on gaming and entertainment platforms, alongside significant exposure risks for high-value targets such as government agencies and academic institutions. Furthermore, the findings empirically confirm the prevalence of credential reuse and repeated victimization. Ultimately, this work establishes a robust empirical foundation for comprehensive threat assessment within the cybersecurity landscape.
📝 Abstract
Infostealer malware infects devices worldwide and harvests their most sensitive contents: credentials, browser sessions, private keys, and access certificates. Yet its impact on victims remains difficult to study without an ethical, legal, and curated research dataset. To close this gap, we build a privacy-preserving pipeline that turns illicitly sourced infostealer logs into a reproducible research artifact, minimizing sensitive data while preserving measurement utility, and use it to construct a dataset of 170,298 victims from logs of multiple infostealer families. Analyzing these victims, we find that the most compromised services mirror the world's most popular platforms, with gaming and entertainment services strongly overrepresented. Within the sample we identify compromised credentials for high-value organizations, including law-enforcement domains, government and military services, and all eight Ivy League universities, as well as substantial exposure of security-critical infrastructure and of financial, remote-access, and development platforms. Victims also show widespread credential reuse and significant revictimization risk, overlapping with phishing and ransomware victim populations. We release the first anonymized victim-level infostealer dataset under controlled access to enable ethical, privacy-preserving, and reproducible research on information security and victim behavior.
Problem

Research questions and friction points this paper is trying to address.

Infostealer malware
victim impact
credential theft
cybersecurity dataset
Innovation

Methods, ideas, or system contributions that make the work stand out.

Infostealer Malware
Privacy-Preserving Pipeline
Data-Driven Analysis
Credential Reuse
Anonymized Dataset
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
A
Arttu Paju
Tampere University, Tampere, Finland
J
Juha Nurmi
Tampere University, Tampere, Finland
D
David Arroyo
Consejo Superior de Investigaciones Científicas (CSIC), Madrid, Spain
S
Sergio Chica Manjarrez
Consejo Superior de Investigaciones Científicas (CSIC), Madrid, Spain
Fran Casino
Fran Casino
Rovira i Virgili University & Athena Research Center
cybersecurityrecommender systemsprivacycognitive securityblockchain
M
Mikko Niemelä
Cyber Intelligence House, Singapore, Singapore
J
Juuso Itkonen
Macquarie University, Sydney, Australia
Joel Scanlan
Joel Scanlan
University of Tasmania
CybersecurityCSAM DeterrenceMaritime Cybersecurity
Constantinos Patsakis
Constantinos Patsakis
University of Piraeus
CryptographyComputer SecurityPrivacyBlockchainCybercrime
Georgios Smaragdakis
Georgios Smaragdakis
Professor of Computer Science, Delft University of Technology (TU Delft)
Internet MeasurementInternet SecurityWeb PrivacyContent DeliveryBig Data