CypherCon 2026
Ransomware vs. Info Stealers: A Comparative Analysis
Steph Shample
Abstract:
In the evolving cybercrime economy, ransomware and information stealers represent two of the most pervasive and damaging classes of malware impacting organizations today. While ransomware inflicts immediate, high-visibility financial disruption through extortion, infostealers operate silently, exfiltrating credentials, authentication tokens, browser artifacts, financial data, and other sensitive assets for resale or use in follow-on attacks. Critically, infostealers increasingly function as enablers for ransomware campaigns, providing privileged access and lateral movement opportunities that amplify the scope and impact of subsequent extortion operations.
This talk delivers a practical, side-by-side comparison of ransomware and information stealers from the perspective of today’s defenders, threat hunters, and incident responders. Attendees will gain clarity on how these threats differ in objectives, infection vectors, operational visibility, persistence mechanisms, and defender blind spots. The session will also evaluate real-world trends, including the limitations of conventional defenses, such as multi-factor authentication and antivirus solutions, against modern infostealer campaigns observed across 2024–2025, and will highlight how the integration of these malware types into unified adversary toolchains is changing detection and response strategies.
By the end of the talk, security practitioners will leave with actionable insights to refine their detection logic, prioritize controls more effectively, and fortify organizational resilience against both ransomware and the stealthier information theft operations that often precede them.
Bonus: This talk has been presented in Europe, and is themed in the style of older video games! (Think Donkey Kong, Pac Man, original Mario brothers, Qbert, and more!)

Steph Shample
Security Researcher
Steph Shample is a seasoned cybersecurity professional with over 22 years of experience spanning military operations, government service, and threat intelligence. She specializes in dark web monitoring, cybercrime patterns, and dark market ecosystems, as well as educating the public on these topics. Previously, Steph served as a Non‑Resident Scholar in the Strategic Technologies & Cyber Security Program at the Middle East Institute, analyzing Iranian cyber strategies, proliferation networks, and regional security dynamics. Her military and civilian deployments, including two tours in Afghanistan, provided hands-on operational experience throughout the Middle East, Central, and South Asia. Shample’s thought leadership is frequently featured in media outlets such as CNN and Stars and Stripes, and she’s a recognized speaker at industry forums like Women in Cybersecurity (WiCYS) and Europe’s DeepSec. A trusted expert in dark web intelligence and more, Shample has been featured on The Needle Stack Podcast, where she discussed AI trends, operational security, and the importance of dark web insights for enterprise defense. Her work empowers organizations to illuminate hidden threats and proactively respond to evolving cyber adversaries.