Info-stealers are lightweight malware that silently extract your saved passwords, browser cookies, and session tokens the instant they run. They’re the most common malware today — usually from pirated software, fake installers, game mods, or “free” tools. Antivirus scans often find nothing because the malware already did its job and left. The order of these steps matters. Do them out of sequence and the attacker keeps access.
This is the most critical step that most people skip. Info-stealers capture your active session tokens — which means the attacker can log into your accounts without needing your password. Changing your password does NOT invalidate existing sessions on most services. You must explicitly sign out of all devices.
Do this right now, even on the infected device if you don’t have another one handy — speed matters more than using a clean device for this step:
Google: Go to myaccount.google.com/device-activity → select each device → Sign out.
Microsoft: Go to account.microsoft.com → Security → Additional security options → Sign out everywhere.
Apple: Apple makes this harder — you need to manually sign out of each device and session individually through your Apple ID settings.
Do the same for banking, social media, email, e-commerce, and any other account you were logged into. If a service asks you for your password to log in, that’s actually good news — it means the attacker doesn’t have an active session there.
After revoking sessions, switch to a device you know is not infected (a family member’s phone, a work computer, a tablet). Log into each account and change your password. Prioritize in this order:
1. Primary email (this is the master key to everything else)
2. Banking and financial accounts
3. Password manager (if you use one)
4. Social media
5. Shopping accounts (Amazon, etc.)
6. Everything else
While changing passwords, also check for email forwarding rules — attackers often add a rule that silently forwards all your email to their address, so they keep getting your password reset links even after you change your password. Check this in your email settings under “Forwarding” or “Rules.”
Do not simply run a virus scan and assume you’re clean. Info-stealers are designed to leave minimal traces, and antivirus tools frequently miss them. A malware scan showing “no threats found” does not mean your device is safe. The only way to be certain is a complete OS reinstall.
Windows: Create a bootable USB from a clean device using Microsoft’s official Media Creation Tool. Boot from the USB, delete all partitions during setup, and do a fresh install. A standard “Reset this PC” is not sufficient for persistent malware.
Mac: Boot into Recovery Mode, open Disk Utility, erase the internal disk, then reinstall macOS.
Before copying any files back to your freshly installed system, scan them with Malwarebytes or Windows Defender. The malware may have come from a file in your Downloads folder, and restoring that file reinfects you immediately. Be especially cautious with executable files (.exe, .msi), scripts, game mods, and anything you downloaded shortly before the infection.
Info-stealers often capture banking credentials, credit card numbers stored in browsers, and enough personal data for identity theft. For the next 30–90 days, monitor your bank accounts and credit cards closely for unauthorized transactions. Consider freezing your credit reports with all three bureaus (Equifax, Experian, TransUnion) — this prevents anyone from opening new accounts in your name. You can freeze and unfreeze for free whenever you need to apply for credit.
Info-stealers are almost always self-inflicted. The most common sources are:
• Pirated software or game cracks — the #1 source of info-stealers. There is no safe website for pirated software. Period.
• Fake installers or “free” tools — downloaded from search results or social media ads
• Game mods from untrusted sources — especially mods that require disabling antivirus to install
• Fake CAPTCHA prompts — “click here to verify you’re human” pages that actually run malicious scripts
• Malicious browser extensions — especially ones that promise free features or “enhanced” functionality
Going forward: never save passwords in your browser (use a dedicated password manager instead), keep your OS and browser updated, and treat any software that asks you to disable your antivirus as malware.
Speed matters. In a session, we can help you revoke sessions across all your accounts, verify no forwarding rules were added, check for persistence mechanisms, and guide you through the OS reinstall — all in real time.