infostealers

Summarize infostealer families, marketplaces, and campaigns for CTI reporting.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill infostealers
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: infostealers
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/infostealers
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill infostealers

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Knowledge cell for infostealers that provides an up-to-date, self-updating knowledge base about infostealer malware, its families, ecosystems, and operational patterns to support threat intelligence analysis and defensive planning.

Core Features & Use Cases

  • Curated threat intel on major infostealer families (e.g., RedLine, Lumma, Vidar, StealC, Rhadamanthys) and MaaS ecosystems, including distribution methods, pricing, and notable campaigns.
  • Historical context and TTP evolution (delivery, persistence, data targets) to inform detection and response strategies.
  • Practical CTI use cases: actor profiling, risk assessment, incident response planning, executive threat briefings, and threat reports.

Quick Start

Query the infostealers knowledge cell to produce a concise briefing on major families, marketplaces, and campaigns for CTI reporting.

Frequently Asked Questions about infostealers

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the current infostealer threat landscape and major malware families?

The infostealer threat landscape is dominated by MaaS ecosystems like RedLine, Lumma, Vidar, StealC, and Rhadamanthys. This knowledge base summarizes their distribution methods, pricing models, data targets, and notable campaigns for CTI reporting.

How do I gather threat intelligence on infostealer malware for CTI reports?

To gather infostealer threat intelligence, query the knowledge cell to produce concise briefings on major families, marketplaces, and campaigns. It delivers structured insights with references suitable for direct ingestion into dashboards and warning intelligence.

Can I use this knowledge base for incident response planning against infostealers?

Yes, you can use it for incident response planning. It provides historical context on TTP evolution including delivery, persistence, and data targets, alongside actor profiling and risk assessment data to inform defensive strategies.

Does this infostealer tracker include law enforcement actions against cybercrime?

Yes, it includes recent law enforcement actions relevant to CTI teams. Tracking these actions alongside threat actors, MaaS models, and distribution channels helps assess the operational status and disruption of infostealer ecosystems.

What data targets and distribution channels do infostealer campaigns use?

Infostealer campaigns target credentials and sensitive system data through various distribution channels. The knowledge base tracks these operational patterns, MaaS pricing, and TTP evolution to support actor profiling and executive threat briefings.

Why should CTI teams track MaaS ecosystems for infostealer malware?

CTI teams track MaaS ecosystems to understand how infostealer malware is distributed and monetized. Monitoring major families, marketplaces, and threat actors provides actionable intelligence for risk assessment and proactive defensive planning.