Storm is a newly advertised infostealer sold as a subscription-based cybercrime service that steals browser credentials, cookies, refresh tokens, cryptocurrency wallet data, documents, messaging app session data, screenshots, and system information. Reporting indicates it targets Chromium and Gecko-based browsers, including Chrome, Edge, Firefox, and Waterfox, while also going after services and apps such as Telegram, Discord, Binance, and Coinbase. Investigators observed victim logs spanning multiple countries, including India, Brazil, the United States, and the United Kingdom, and a criminal panel showing more than 1,700 log entries.
The malware’s distinguishing feature is server-side decryption, which allows stolen browser data to be exfiltrated in encrypted form and decrypted on attacker-controlled infrastructure rather than on the victim device. That design reduces endpoint telemetry, helps evade antivirus detection, and reportedly undermines Chrome’s App-Bound Encryption protections. Storm also includes automated cookie restoration and the use of geographically matched SOCKS5 proxies to re-establish authenticated sessions, enabling attackers to bypass password-based defenses and, in some cases, render MFA ineffective while accessing SaaS accounts, Microsoft 365, internal tools, and cloud environments.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
SC Media amplified Varonis' findings, emphasizing that Storm undermines Google's App-Bound Encryption introduced in Chrome 127 and targets browsers such as Chrome, Edge, Firefox, and Waterfox. The coverage also noted Storm's theft of crypto wallet and messaging app data and its ability to capture screenshots.
Varonis published research describing Storm's ability to steal browser credentials, cookies, refresh tokens, crypto wallet data, messaging app session data, screenshots, and system information, then exfiltrate encrypted data for server-side decryption. The report highlighted that Storm supports Chromium and Gecko-based browsers and can restore stolen cookies to hijack authenticated sessions, potentially bypassing password protections and some MFA controls.
At the time of Varonis Threat Labs' investigation, Storm's panel reportedly showed 1,715 log entries affecting users across multiple countries, including India, Brazil, the United States, and the United Kingdom. This indicated the malware was already being used in active credential and session theft operations.
Storm, a new subscription-based infostealer service, was advertised on underground cybercrime forums in early 2026. It was marketed in multiple tiers and designed for multi-user criminal operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.