logo

Storm Infostealer Sold as Service, Targets Browsers, Wallets and Accounts

ID: dd54e1e8-e360-536a-866d-d624ce4ac2b0

STIX ID: report--dd54e1e8-e360-536a-866d-d624ce4ac2b0

Feed Name: HackRead

Threat Score
80/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Varonis Threat Labs identified "Storm" infostealer (early 2026), a subscription-based malware that harvests browser credentials, session cookies, crypto wallets, and messaging account data from Chromium- and Gecko-based browsers. Using a server-side decryption technique that circumvents Chrome's App-Bound Encryption, Storm exfiltrates data to attacker-controlled servers, supports multi-monitor screenshots, and is sold commercially with evidence of active use in the wild (logs showing 1,715 victim entries across India, Brazil, the US, and the UK).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.