logo

Profiling CSAM Consumers Using Infostealers Data

ID: 5dd540e1-821b-5f5b-9625-df4b6bc08529

STIX ID: report--5dd540e1-821b-5f5b-9625-df4b6bc08529

Feed Name: infostealers.com

Threat Score
75/100

Date Published: 2024-12-21

Date Updated: 2026-04-28

Author: InfoStealers

...
...

This report presents a reverse-investigation methodology that uses data from InfoStealer logs (credentials, cookies, browser-saved wallets, and hardware serial numbers) to map Dark Web CSAM domains to infected devices, pivot from device identifiers to other leaked sources, and thereby profile and deanonymize site users; the author includes case examples illustrating identification of fake and real identities and discusses limits and scalability of the approach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.