logo

The silent “Storm”: New infostealer hijacks sessions, decrypts server-side

ID: 89ed7432-e6a0-597f-9c37-f54a0e3ffc5f

STIX ID: report--89ed7432-e6a0-597f-9c37-f54a0e3ffc5f

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-13

Date Updated: 2026-04-20

Author: Sponsored by Varonis

...
...

A newly marketed infostealer called Storm (subscription-based) collects browser credentials, session cookies, autofill, crypto wallets, messaging data and files, and sends encrypted browser stores for server-side decryption to evade endpoint detection. Storm includes automated cookie restore/session-hijack features (using refresh tokens and geographically-matched SOCKS5 proxies), team/role management, operator-controlled VPS routing to resist takedowns, and active log evidence across multiple countries; pricing tiers and build characteristics are provided alongside basic IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.