Find notable cyber news and cases, enriched with sources, timelines, and signals.

Storm infostealer server-side decryption activity

Malware Activity
First reported
Last updated
Happening score
H score 18
2 unique sources, 2 articles

Summary

Hide ▲

The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption, raising the risk of session hijacking and account takeover. It also targets Telegram, Signal, Discord, and browser-stored tokens, making compromised endpoints a gateway to cloud and SaaS access.

Related Happenings

ShinyHunters-linked Salesforce intrusion campaign

Campaign
H score45 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

Helix vishing and SharePoint data-extortion campaign

Campaign
H score38 First: 09.07.2026 20:08 Last: 09.07.2026 20:08 Sources 1

About this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...

Bluekit adopts rrweb-based BitM session streaming for login theft

Technical Analysis
H score34 First: 25.06.2026 18:00 Last: 25.06.2026 18:00 Sources 1

About this happening: Bluekit has added browser-in-the-middle (BitM) login theft to its phishing stack, increasing the risk of session-token theft and account takeover. The mechanism us...

Gaslight macOS implant with Telegram C2 and prompt-injection payload

Malware Activity
H score29 First: 25.06.2026 12:23 Last: 25.06.2026 12:23 Sources 1

About this happening: A previously undocumented macOS implant named Gaslight combines Telegram bot API C2, persistent shell control, and file exfiltration with a built-in prompt-i...

Timeline

  1. 01.04.2026 03:00 2 articles · 3mo ago

    Varonis discloses Storm server-side decryption infostealer

    Initial Disclosure

    Varonis discloses Storm, an infostealer that emerged on underground cybercrime networks in early 2026 and steals browser credentials, session cookies, crypto wallets, documents, screenshots, and messaging-session data before shipping encrypted files to attacker infrastructure for server-side decryption. The malware handles both Chromium and Gecko-based browsers, targets Telegram, Signal, Discord, and browser extensions and desktop apps for wallets, and can silently restore authenticated sessions with a Google Refresh Token plus a geographically matched SOCKS5 proxy. The investigation also found 1,715 entries linked to activity across multiple countries, indicating ongoing malicious campaigns.

    Show sources