The playbookstealer · information stealer

Infostealer

Commodity malware that runs once on a machine, empties every credential store it can reach, and leaves. Browser passwords, session cookies, crypto wallet files, VPN and messaging configs, then a screenshot and a file listing. The output is a stealer log.

Why it matters to you

The malware is not the incident, the log is. By the time anyone finds the infection the credentials have been sold, and cleaning the endpoint changes nothing about that. Assume every secret that machine could reach is public and rotate on that basis, sessions included.

Where we meet it

The same log surfaces in more than one shop, resold and repackaged, so a credential's first appearance and its last can be weeks apart. Freshness is what the price tracks, which means the cheap ones are the ones that have already been worked through.

Where this term stops being vocabulary

Sherlog is where you watch it happen to you

Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.