logo

Storm: 2026’s Newest Infostealer Bypasses Chrome to Hijack Your MFA Sessions

ID: b5c4e3ac-2733-575e-add6-c3224e660cca

STIX ID: report--b5c4e3ac-2733-575e-add6-c3224e660cca

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Storm is a newly identified infostealer MaaS (early 2026) that harvests encrypted browser credentials, session cookies, and cryptocurrency wallets then ships the encrypted files to attacker infrastructure for server-side decryption—bypassing modern endpoint protections and enabling account takeover via stolen sessions; it is sold in tiered subscriptions, persists after subscription expiry, and supports both Chromium- and Gecko-based browsers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.