Information-stealing malware (ISM) is redefining the cybersecurity threat landscape, particularly through its integration into the malware-as-a-service (MaaS) ecosystem. Traditional threat models, while effective against generic vulnerabilities, struggle to keep pace with the sophisticated and evolving tactics of ISMs. These advanced threats exploit software vulnerabilities, bypass conventional defenses, and thrive on usability-security trade-offs, leaving critical systems exposed. This research delves into the intricate attack vectors of ISMs, uncovering gaps in existing frameworks. By leveraging the MITRE ATT&CK framework and focusing on Tactics, Techniques, and Procedures (TTPs), we introduce a refined threat model designed to outmaneuver these challenges. The proposed approach offers precise, actionable strategies to combat ISM threats, setting a new standard for resilience in a world of ever-advancing cyber adversaries.
National Institute of Standards and Technology (NIST) (2024) Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf
Exploding Topics (2024) 80 + Password Statistics for 2023: Data on Usage, Attacks & Attitudes. https://explodingtopics.com/blog/password-stats
Roomi, S.A. and Li, F. (2023) A Large-Scale Measurement of Website Login Policies. In: 32 nd USENIX Security Symposium ( USENIX Security 23), USENIX Association, 2061-2078. https://www.usenix.org/conference/usenixsecurity23/presentation/al-roomi
Fagan, M., Albayram, Y., Khan, M.M.H. and Buck, R. (2017) An Investigation into Users’ Considerations towards Using Password Managers. Human - Centric Computing and Information Sciences , 7, Article No. 12. https://doi.org/10.1186/s13673-017-0093-6
Research and Markets (2024) Password Manager Global Market Report 2025. https://www.researchandmarkets.com/reports/5951840
Goodin, D. (2023) LastPass Says Employee’s Home Computer was Hacked and Corporate Vault Taken. https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/
Greig, J. (2023) Norton LifeLock Says 925,000 Accounts Targeted by Credential-Stuffing Attacks. https://therecord.media/norton-lifelock-says-925000-accounts-targeted-by-credential-stuffing-attacks
Abrams, L. (2023) Bitwarden Password Vaults Targeted in Google ads Phishing Attack. https://www.bleepingcomputer.com/news/security/bitwarden-password-vaults-targeted-in-google-ads-phishing-attack/
Ilascu, I. (2024) Fake Bitwarden Sites Push New Zenrat Password-Stealing Malware. https://www.bleepingcomputer.com/news/security/fake-bitwarden-sites-push-new-zenrat-password-stealing-malware/
Okta, Inc. (2023) Passwordless Authentication for Customer Identity. https://www.okta.com/customer-identity/passwordless/
Kotadia, M. (2004) Gates Predicts Death of the Password. https://www.cnet.com/news/privacy/gates-predicts-death-of-the-password/
Information Is Beautiful (2024) World’s Biggest Data Breaches & Hacks. https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks
Orenstein, G. (2023) Understanding Bitwarden Architecture. https://bitwarden.com/blog/understanding-bitwarden-architecture/
Kgretzky/Evilginx2 (2024) Advanced Phishing with Two-Factor Authentication Bypass. https://github.com/kgretzky/evilginx2
Microsoft Threat Intelligence (2023) Dev-1101 Enables High-Volume AiTM Campaigns with Open-Source Phishing Ki. https://www.microsoft.com/en-us/security/blog/2023/03/13/dev-1101-enables-high-volume-aitm-campaigns-with-open-source-phishing-kit/
Proofpoint (2023) ZenRAT: Malware Brings More Chaos than Calm. https://www.proofpoint.com/us/blog/threat-insight/zenrat-malware-brings-more-chaos-calm
Github Issue #3166: Vulnerability: Sensitive Information Is Not Purged from Process Memory on app Lock or Logout. https://github.com/bitwarden/clients/issues/3166
Bitwarden Community (2024) Autofill: Should We Turn It Off? https://community.bitwarden.com/t/autofill-should-we-turn-it-off/52331/4
Acar, G. (2017) No Boundaries for User Identities: Web Trackers Exploit Browser Login Managers. https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/
Flashpoint (2023) Bitwarden Password Pilfering: Understanding the Risks. https://flashpoint.io/blog/bitwarden-password-pilfering/
web.dev, (2024) Third-Party Content and Privacy. https://web.dev/learn/privacy/third-parties
Silver, D., Jana, S., Boneh, D., Chen, E. and Jackson, C. (2014) Password Managers: Attacks and Defenses. In: 23 rd USENIX Security Symposium ( USENIX Security 14). USENIX Association, 449-464. https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/silver
Bitwarden Community (2024) Phishing Website: Bitwardenlogin.com. https://community.bitwarden.com/t/phishing-website-bitwardenlogin-com/49704
Bitwarden (2023) Bitwarden Trademark Guidelines: Standards for Use. https://github.com/bitwarden/server/blob/main/TRADEMARK_GUIDELINES.md#standards-for-use
Bitwarden Community (2023) Phishing Website: Bitwardenlogin.com. https://community.bitwarden.com/t/phishing-website-bitwardenlogin-com/49704/22?page=2
Morris, R. and Thompson, K. (1978) Password Security: A Case History. Bell Laboratories , 594-597.
Palant, W. (2022) LastPass Breach: The Significance of These Password Iterations. https://palant.info/2022/12/28/lastpass-breach-the-significance-of-these-password-iterations/
Palant, W. (2023) A Year after the Disastrous Breach, LastPass Has Not Improved. https://palant.info/2023/09/05/a-year-after-the-disastrous-breach-lastpass-has-not-improved/#the-initial-advisory
(2024) Password Hashing Competition and Our Recommendation for Hashing Passwords: Argon2. https://www.password-hashing.net/
Bitwarden Community (2024) Increasing KDF Iterations. https://community.bitwarden.com/t/increasing-kdf-interations/48059/12
Bitwarden (2024) Account Encryption Key—Rotate Your Encryption Key. https://bitwarden.com/help/account-encryption-key/#rotate-your-encryption-key
KeePass Help Center (2024) KeePass 2.x Setup. https://keepass.info/help/v2/setup.html
SourceForge (2023) Keepass Discussion Thread: Someone Can Read the Passwords Using Export Trigger. https://sourceforge.net/p/keepass/discussion/329220/thread/a146e5cf6b/
Malwarebytes (2023) Clever Malvertising Attack Uses Punycode to Look Like Legitimate Website. https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website
Bogner, M. (2016) MitM Attack against KeePass 2’s Update Check. https://bogner.sh/2016/03/mitm-attack-against-keepass-2s-update-check/
(2025) Icloud Data Security Overview. https://support.apple.com/en-us/102651
(2025) Make Your Passkeys and Passwords Available on All Your Devices with Iphone and Icloud Keychain. https://support.apple.com/guide/iphone/passwords-devices-iph82d6721b2/ios
Karthick, M.P. (2023) Compromising Google Accounts: Malwares Exploiting Undocumented OAuth2 Functionality for Session Hijacking. https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking
Microsoft (2025) Microsoft Wallet. https://www.microsoft.com/en-us/edge/features/wallet?form=MA13FJ
(2025) Darklane Security Alerts and Dark Web Monitoring in Dashlane. https://support.dashlane.com/hc/en-us/articles/360000038180-Security-alerts-and-Dark-Web-Monitoring-in-Dashlane#dwmmp
Guenni (2023) Vulnerabilities in Bitwarden Password Manager Browser Extension Can Reveal Passwords. https://borncity.com/win/2023/03/10/vulnerabilities-in-bitwarden-password-manager-browser-extension-can-reveal-passwords/?utm_source=chatgpt.com
Bajwa, H. (2024) Password Managers Hacked: A Comprehensive Overview. https://www.beyondidentity.com/resource/password-managers-hacked-a-comprehensive-overview
Bitwarden Community (2024) Clipboard Security. https://community.bitwarden.com/t/clipboard-security/36507/25
Kim, J., van Schaik, S., Genkin, D. and Yarom, Y. (2023) iLeakage: Browser-Based Timerless Speculative Execution Attacks on Apple Devices. Association for Computing Machinery, 2038-2052. https://doi.org/10.1145/3576915.3616611
Gibraltar Solutions (2024) Malware-As-a-Service: A Growing Threat to Modern Businesses. https://gibraltarsolutions.com/blog/malware-as-a-service/
Darktrace, (2023) End of Year Threat Report 2023. https://cdn.prod.website-files.com/626ff19cdd07d1258d49238d/65d744bd0fc63765c5c1442d_Darktrace%20-%20End%20of%20Year%20Threat%20Report%202023.pdf
SEKOIA (2023) Traffers: A Deep Dive into the Information Stealer Ecosystem. https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem/
The Record (2024) Youtube Infostealer Campaign Uses Cracked and Pirated Video Games. https://therecord.media/youtube-infostealer-campaign-cracked-pirated-video-games
Flashpoint (2023) SEO Poisoning: Threat Actors Using Search Engines. https://flashpoint.io/blog/seo-poisoning-threat-actors-using-search-engines/
Flare (2024) Telegram Fraud: The Hidden Criminal Market. https://flare.io/learn/resources/blog/telegram-fraud/
Sekoia (2023) Overview of the Russian-Speaking Infostealer Ecosystem: The Logs. https://blog.sekoia.io/overview-of-the-russian-speaking-infostealer-ecosystem-the-logs/
Webz.io (2024) XSS: The Top Russian Dark Web Forum. https://webz.io/dwp/xss-the-top-russian-dark-web-forum/
Webz.io (2024) How Dark Web Data Discovers the Hackers behind Hacking Forums. https://webz.io/blog/dark-web-api/how-dark-web-data-discovers-the-hackers-behind-hacking-forums/
Horsnell, C. (2024) The Problem with Developers Only Focusing on Functional Requirements. https://medium.com/@chrishorsnell/the-problem-with-developers-only-focusing-on-functional-requirements-bbef26d3a4b1
Trellix (2024) Utilizing Adaptive Defense Model against Information Stealers. https://www.trellix.com/blogs/research/utilizing-adaptive-defense-model-against-information-stealers/
Li, W.Z., He, W., Akhawe, D. and Song, D. (2014) The Emperor’s New Password Manager: Security Analysis of Web-Based PASSWORD managers. In: 23 rd USENIX Security Symposium ( USENIX Security 14). USENIX Association, 465-479. https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/li_zhiwei
Shahandashti, S.F. and Carr, M. (2020) Revisiting Security Vulnerabilities in Commercial Password Managers. https://arxiv.org/abs/2003.01985
Nisenoff, A., Golla, M., Wei, M., Hainline, J., Szymanek, H., Braun, A., et al. (2023) A Two-Decade Retrospective Analysis of a University’s Vulnerability to Attacks Exploiting Reused Passwords. In: 32 nd USENIX Security Symposium ( USENIX Security 23), USENIX Association, 5127-5144. https://www.usenix.org/conference/usenixsecurity23/presentation/nisenoff-retrospective
Hansson, D.H. (2024) Passwords Have Problems, but Passkeys Have More. https://world.hey.com/dhh/passwords-have-problems-but-passkeys-have-more-95285df9#
Microsoft (2024) Storing Data to and Reading from the Clipboard. https://learn.microsoft.com/en-us/dotnet/visual-basic/developing-apps/programming/computer-resources/storing-data-to-and-reading-from-the-clipboard?redirectedfrom=MSDN
Luevanos, C., Elizarraras, J., Hirschi, K. and Yeh, J.-h. (2017) Analysis on the Security and Use of Password Managers. 2017 18 th International Conference on Parallel and Distributed Computing , Applications and Technologies ( PDCAT ), 18-20 December 2017, 17-24. https://doi.org/10.1109/PDCAT.2017.00013
Bitwarden (2024) Unlock with Pin—Understanding Unlock vs. Log in. https://bitwarden.com/help/unlock-with-pin/#understanding-unlock-vs-log-in
Hive Systems (2023) Are Your Passwords in the Green? https://www.hivesystems.com/blog/are-your-passwords-in-the-green
Abuse.ch (2024) Raccoon Information Stealer Sample. https://bazaar.abuse.ch/sample/022432f770bf0e7c5260100fcde2ec7c49f68716751fd7d8b9e113bf06167e03/
S2W Blog (2024) Raccoon Stealer Is Back with a New Version. https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d
S. Community (2022) Raccoon Stealer Indicators of Compromise (IOCS). https://raw.githubusercontent.com/SEKOIA-IO/Community/refs/heads/main/IOCs/raccoonstealer/raccoon_stealer_iocs_20220628.csv