BR100 Decreased By (-0.16%)
BR30 Decreased By (-0.26%)
KSE100 Decreased By (-0.21%)
KSE30 Decreased By (-0.28%)
AGHA 6.56 Increased By ▲ 0.04 (0.61%)
BECO 4.27 Decreased By ▼ -0.05 (-1.16%)
BML 57.51 Increased By ▲ 0.47 (0.82%)
BOP 29.08 Decreased By ▼ -0.17 (-0.58%)
CNERGY 12.52 Increased By ▲ 0.13 (1.05%)
CSIL 5.11 Decreased By ▼ -0.03 (-0.58%)
FCCL 52.12 Increased By ▲ 0.05 (0.1%)
FFL 14.03 Increased By ▲ 0.02 (0.14%)
FNEL 1.14 Decreased By ▼ -0.02 (-1.72%)
KEL 6.05 Increased By ▲ 0.09 (1.51%)
KOSM 5.38 No Change ▼ 0.00 (0%)
LOTCHEM 26.38 Decreased By ▼ -0.22 (-0.83%)
MLCF 90.63 Decreased By ▼ -0.32 (-0.35%)
NBP 158.42 Decreased By ▼ -2.32 (-1.44%)
NCPL 50.97 Decreased By ▼ -0.26 (-0.51%)
NPL 54.98 Decreased By ▼ -1.01 (-1.8%)
OGDC 306.12 Decreased By ▼ -2.54 (-0.82%)
PACE 9.78 Increased By ▲ 0.21 (2.19%)
PAEL 33.96 Increased By ▲ 0.23 (0.68%)
PIBTL 13.52 Decreased By ▼ -0.06 (-0.44%)
PPL 218.94 Increased By ▲ 0.59 (0.27%)
PRL 93.07 Increased By ▲ 1.95 (2.14%)
PTC 58.84 Decreased By ▼ -1.25 (-2.08%)
SSGC 23.06 Increased By ▲ 0.02 (0.09%)
TBL 9.33 Increased By ▲ 0.37 (4.13%)
TELE 7.17 No Change ▼ 0.00 (0%)
TPL 20.17 Increased By ▲ 0.76 (3.92%)
TPLP 12.38 Increased By ▲ 0.58 (4.92%)
TREET 23.72 Increased By ▲ 1.47 (6.61%)
TRG 55.29 Increased By ▲ 0.07 (0.13%)

ISLAMABAD: A leading cybersecurity company Friday warned Pakistani companies to hire digital risk protection services to avoid “infostealer infections” attacks used to steal corporate data.

A new research by Kaspersky Digital Footprint (DFI) has discovered that more than one-third of infostealer infections start when users run files directly from temporary browser folders, showing that user behaviour remains a key factor behind credential theft. Just 32 percent of infostealer attacks use process injection and living off the land techniques, typical of advanced malware families

Kaspersky DFI researchers analyzed 5 million infostealer log files discovered on the dark web in 2025. These logs, which contain data stolen from compromised devices such as account credentials, browser cookies and system metadata, also revealed the original locations of malicious files on infected machines.

The most common location was the Windows temporary directory, C:\Users\ AppData\ Local\Temp, which accounted for approximately 35 percent of all observed cases. This folder is commonly used to store files downloaded from the internet before they are explicitly saved by a user: a significant share of infections occurs when users directly launch downloaded files, without attackers relying on sophisticated evasion techniques.

The analysis indicates that infections are often linked to two risky user actions: downloading software from untrusted sources and attempting to activate software illegally. In many cases, victims follow instructions provided by threat actors and disable security software before running malicious files. According to the research, many malicious files were disguised as legitimate software installers, activators or game modifications. While game mods remain a common lure, attackers frequently adapt the same techniques to distribute virtually any type of software.

“Infostealers surged in 2025, with infections rising 59 percent year over year. Our analysis shows that user behaviour remains a key factor behind many of these compromises.

Copyright Business Recorder, 2026

Comments

200 characters remaining