Storm infostealer server-side decryption activity
Malware Activity
Summary
Hide ▲
Show ▼
The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption, raising the risk of session hijacking and account takeover. It also targets Telegram, Signal, Discord, and browser-stored tokens, making compromised endpoints a gateway to cloud and SaaS access.
Related Happenings
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
CrashStealer macOS information stealer activity
Malware Activity
H score10
First: 13.07.2026 20:36
Last: 13.07.2026 20:36
Sources 1
About this happening:
CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
CrashStealer macOS information stealer activity
Malware ActivityAbout this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Bluekit adopts rrweb-based BitM session streaming for login theft
Technical Analysis
H score34
First: 25.06.2026 18:00
Last: 25.06.2026 18:00
Sources 1
About this happening:
Bluekit has added browser-in-the-middle (BitM) login theft to its phishing stack, increasing the risk of session-token theft and account takeover. The mechanism us...
Bluekit adopts rrweb-based BitM session streaming for login theft
Technical AnalysisAbout this happening: Bluekit has added browser-in-the-middle (BitM) login theft to its phishing stack, increasing the risk of session-token theft and account takeover. The mechanism us...
Gaslight macOS implant with Telegram C2 and prompt-injection payload
Malware Activity
H score29
First: 25.06.2026 12:23
Last: 25.06.2026 12:23
Sources 1
About this happening:
A previously undocumented macOS implant named Gaslight combines Telegram bot API C2, persistent shell control, and file exfiltration with a built-in prompt-i...
Gaslight macOS implant with Telegram C2 and prompt-injection payload
Malware ActivityAbout this happening: A previously undocumented macOS implant named Gaslight combines Telegram bot API C2, persistent shell control, and file exfiltration with a built-in prompt-i...
Timeline
-
01.04.2026 03:00 2 articles · 3mo ago
Varonis discloses Storm server-side decryption infostealer
Initial DisclosureVaronis discloses Storm, an infostealer that emerged on underground cybercrime networks in early 2026 and steals browser credentials, session cookies, crypto wallets, documents, screenshots, and messaging-session data before shipping encrypted files to attacker infrastructure for server-side decryption. The malware handles both Chromium and Gecko-based browsers, targets Telegram, Signal, Discord, and browser extensions and desktop apps for wallets, and can silently restore authenticated sessions with a Google Refresh Token plus a geographically matched SOCKS5 proxy. The investigation also found 1,715 entries linked to activity across multiple countries, indicating ongoing malicious campaigns.
Show sources
- New 'Storm' Infostealer Remotely Decrypts Stolen Credentials — www.infosecurity-magazine.com — 02.04.2026 17:15
- The silent “Storm”: New infostealer hijacks sessions, decrypts server-side — www.bleepingcomputer.com — 13.04.2026 17:05