New 'Storm' Infostealer Remotely Decrypts Stolen Credentials
ID: 082d58cb-243a-5de6-bc40-c49dd3bf1e22
STIX ID: report--082d58cb-243a-5de6-bc40-c49dd3bf1e22
Feed Name: Infosecurity Magazine (News)
Varonis researchers reported a new infostealer called Storm that emerged in early 2026 and steals saved passwords, session cookies, autofill data, Google tokens, credit cards, browser and desktop crypto wallets, documents, screenshots and messaging session data; it exfiltrates encrypted files to attacker servers for decryption and automates session restoration using Google refresh tokens and geographically matched SOCKS5 proxies, enabling silent account takeovers and fraud, and has been observed in panels with thousands of entries across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
