Filter by Tags

One value per dimension, and multiple Topics. Filters across groups narrow results; Topics match any selected value.
3D animation of a panicked, overheating laptop with a screaming face and fiery circuit boards on its screen, melting ice cubes on top, surrounded by menacing red computer worms in a dark server room.
#WhatFraudstersLike #Malware #AccountTakeover #FraudPrevention #LetsTalkFraud

Fraudsters Like Malware!

The infected device still works. That is often the problem. While its owner reads email, shops, approves payments, or signs into work, malicious software turns the same trusted device into a source of passwords, sessions, financial data, and access.

In 2025, U.S. authorities identified at least 1.7 million instances in which Lumma infostealer stole information. Its targets included browser data, autofill details, email and banking credentials, and cryptocurrency seed phrases.[ref] One malware family supplied raw material for many different crimes.

How fraudsters turn malware into money:

🔑 Credentials and session theft - Infostealers collect passwords, browser cookies, autofill data, card details, screenshots, and device information. A stolen active session gives a criminal access after the victim has already completed authentication. Changing only the password does not reliably close every stolen session.

🏦 Account takeover and payment fraud - Banking malware captures login information, monitors activity, overlays false screens, or gives criminals remote control of the device. The resulting access supports unauthorized transfers, wallet theft, fraudulent purchases, and abuse of email or business accounts.

📦 The first payload is only the lobby - Loaders establish a foothold and fetch the criminal's next tool: an infostealer, remote-access malware, ransomware, or another specialist payload. Access gathered by one operator is also sold to another. Malware has its own supply chain - apparently crime needed subcontractors too.

🔒 Ransomware and data extortion - Malware encrypts systems, disrupts operations, steals data, and creates pressure to pay. FBI IC3 received more than 3,600 ransomware complaints with over $32 million in reported losses in 2025; the figure excludes many business interruption and recovery costs and covers only reports submitted through IC3.[ref]

🤖 Botnets and criminal proxies - Infected computers, phones, routers, and smart devices become rented infrastructure for spam, credential attacks, DDoS, malicious traffic, and concealment of a criminal's real location. The device owner pays for the connection; somebody else gets the business model.

🎣 The victim is recruited into installation - Phishing, fake updates, cracked software, malicious advertisements, poisoned search results, compromised websites, and ClickFix-style instructions lead people to run the malware themselves. ENISA observed infostealers delivered through cracked software, phishing pages, public code repositories, fake CAPTCHA pages, cloud storage, and video-platform links.[ref]

What to do:

For individuals:

- Keep the operating system, browser, applications, security protection, and router firmware supported and updated.

- Install software through official stores or verified publisher websites. Avoid cracks, unsolicited updates, and instructions telling you to paste or run commands to prove you are human.

- Use unique passwords and MFA or passkeys. These controls reduce exposure, but they do not make an infected device trustworthy.

- If infection is suspected, disconnect the device from networks and seek competent help. From a separate clean device, contact affected financial providers, change exposed credentials, revoke active sessions, and check email forwarding rules and account recovery details.

For organizations:

- Combine endpoint detection and response, application control, least privilege, patching, email and web filtering, and network segmentation. No single control sees every payload.

- Monitor for stolen-session abuse, unusual data transfers, new persistence, disabled security tools, and access from unmanaged devices.

- Protect privileged administration and payment approval with hardened, separated workflows rather than ordinary browsing devices.

- Maintain tested, isolated backups and an exercised incident-response process. Preserve evidence before rebuilding affected systems.

Malware is not the fraud itself. It is the highway that enables many frauds to happen and scale.