A Data-Driven Analysis of Infostealer Malware Victims
Researchers analyze 170,298 infostealer victims and release an anonymized dataset under controlled access.
A cs.CR paper describes a privacy-preserving pipeline that turns illicit infostealer logs into a research dataset of 170,298 victims across multiple families. The most compromised services mirror popular platforms, with gaming and entertainment overrepresented, and the sample includes credentials for law-enforcement, government and military services, all eight Ivy League universities, and security, financial, remote-access, and development platforms. Victims show widespread credential reuse, revictimization risk, and overlap with phishing and ransomware victim populations. The authors release the first anonymized victim-level dataset under controlled access.
- Privacy-preserving pipeline built a dataset of 170,298 infostealer victims
- Compromised services track popular platforms, with gaming and entertainment overrepresented
- Sample includes law-enforcement, government, military, and all eight Ivy League domains
- Victims show credential reuse and overlap with phishing and ransomware populations
- Anonymized victim-level dataset is released under controlled access
Full article181 words · extracted from arxiv.org · click to collapse
Infostealer malware infects devices worldwide and harvests their most sensitive contents: credentials, browser sessions, private keys, and access certificates. Yet its impact on victims remains difficult to study without an ethical, legal, and curated research dataset. To close this gap, we build a privacy-preserving pipeline that turns illicitly sourced infostealer logs into a reproducible research artifact, minimizing sensitive data while preserving measurement utility, and use it to construct a dataset of 170,298 victims from logs of multiple infostealer families. Analyzing these victims, we find that the most compromised services mirror the world's most popular platforms, with gaming and entertainment services strongly overrepresented. Within the sample we identify compromised credentials for high-value organizations, including law-enforcement domains, government and military services, and all eight Ivy League universities, as well as substantial exposure of security-critical infrastructure and of financial, remote-access, and development platforms. Victims also show widespread credential reuse and significant revictimization risk, overlapping with phishing and ransomware victim populations. We release the first anonymized victim-level infostealer dataset under controlled access to enable ethical, privacy-preserving, and reproducible research on information security and victim behavior.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.30070