Threat reportMalwareTL-2026-0355
Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS Sessions
Storm Infostealer (v0.0.2.0 Gunnar) (TL-2026-0355), also tracked as Storm Stealer, is a high-severity malware campaign scored CVSS 8.1, first published 2026-04-13. It is attributed to StormStealer (Russia) with medium confidence, affects Google Chrome (and Chromium-based browsers), maps to 32 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 26 indicators of compromise.
- CVSS
- 8.1/10High
- CVEs
- 0None referenced
- Techniques
- 32MITRE ATT&CK
- Actors
- 1StormStealer
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-0355
- Threat ID
- TL-2026-0355
- Also known as
- Storm Stealer, Storm MaaS, StormStealer v0.0.2.0 Gunnar
- Severity
- HIGH
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- StormStealer
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- enterprise SaaS tenants, financial services, cryptocurrency, technology, hosting / cPanel operators, social media users, small and medium business
- Target regions
- India, United States, Brazil, Indonesia, Ecuador, Vietnam, Global
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Storm Infostealer (v0.0.2.0 Gunnar)
Malware and tooling: Storm Infostealer, StormStealer v0.0.2.0 Gunnar, MSVC / msbuild (C++ Windows binary ~460 KB), Storm Cookie Restoration Panel
How Storm Infostealer (v0.0.2.0 Gunnar) works
Storm is a C++ Windows infostealer sold as a subscription service on underground forums that bypasses Chrome's App-Bound Encryption (introduced July 2024) by shipping raw encrypted browser databases, cookies, autofill, and wallet files to attacker-controlled infrastructure where decryption is performed server-side. A built-in Cookie Restoration Panel uses Google Refresh Tokens routed through geographically matched SOCKS5 proxies to silently resume authenticated SaaS sessions, rendering password and MFA controls irrelevant. Varonis Threat Labs disclosed 1,715 victim log entries in the operator panel spanning India, US, Brazil, Indonesia, Ecuador, and Vietnam at the time of analysis, indicating an active global campaign.
Storm Infostealer is a Malware-as-a-Service credential theft platform first surfaced on underground cybercrime forums on December 12, 2025 under the seller handle ''StormStealer'' (forum ID 221756) and publicly disclosed by Varonis Threat Labs in April 2026. The current build, v0.0.2.0 codename ''Gunnar'', is a ~460 KB C++ (MSVC/msbuild) Windows-only binary that operates almost entirely in memory to reduce host telemetry.
Storm''s defining innovation is its rejection of local credential decryption. Prior-generation stealers (RedLine, StealC, Raccoon, Lumma) loaded SQLite at runtime against Chromium ''Login Data'' and ''Cookies'' stores and invoked DPAPI/CryptUnprotectData or Chrome''s app-bound decryption routines on the victim host — activity that EDR and endpoint DLP products have learned to hook and alert on. Storm instead copies the raw encrypted SQLite databases, the App-Bound-Encrypted key material, and Firefox/Gecko credential vaults (targeting Waterfox and Pale Moon in addition to mainline Firefox) and exfiltrates them wholesale to operator-controlled VPS infrastructure. Decryption is performed server-side on hardware outside the defender''s visibility, completely sidestepping Chrome 127''s App-Bound Encryption mitigation that Google shipped in July 2024.
Collection scope is broad: saved passwords, session cookies, autofill forms, credit-card records, Google account tokens, browsing history, Telegram/Signal/Discord session blobs, crypto wallet files from both browser extensions and desktop applications (Coinbase, Binance, Blockchain.com, Crypto.com), a configurable file grabber that sweeps user document directories, system information fingerprints, and multi-monitor GDI screen captures. Data is processed in memory and staged before exfiltration over the C2 channel.
Storm''s operator backend, the Cookie Restoration Panel, is the feature that transforms raw stolen cookies into live SaaS compromise. An operator supplies a harvested Google Refresh Token (or equivalent session artifact) together with a SOCKS5 proxy selected to match the victim''s geographic origin, and the panel silently rehydrates an authenticated browser session. Because the session was established before MFA, password changes, refresh-token rotation, and conditional access policies gated on location do not trigger. Varonis explicitly ties this workflow to its prior Cookie-Bite and SessionShark research, which demonstrated that stolen Azure Entra ID session cookies completely bypass MFA on Microsoft 365 and Azure tenants. A single compromised employee browser can therefore hand an operator authenticated access to SaaS platforms, internal admin consoles, and cloud tenants without triggering a single password-based alert.
Operator infrastructure is deliberately layered to defeat takedown: affiliates connect personal VPNs into Storm''s central servers, and stolen data routes through the operator''s own VPS node first so that abuse complaints and subpoenas land on disposable infrastructure while the central collection server remains insulated. The platform supports team management with role-based permissions (targeting organised criminal crews) and auto-classifies stolen credentials by service domain (Google, Facebook, Twitter/X, cPanel).
Commercial terms are aggressive: $300 for a 7-day demo, $900/month for a standard license, and $1,800/month for a team license that provides 100 concurrent worker seats and 200 builds; a separate crypter must be procured by the buyer. Critically, builds keep running after a subscription lapses — harvested data continues to be shipped to operator infrastructure regardless of license status, producing long-tail collection from abandoned campaigns.
Evidence of active exploitation is unambiguous. At the time of Varonis''s investigation the panel held 1,715 distinct victim log entries spanning India, the United States, Brazil, Indonesia, Ecuador, Vietnam, and other countries, with varied IP ranges, ISPs, and data volumes that are inconsistent with test telemetry. No nation-state attribution has been made; the platform appears to be financially motivated eCrime targeting enterprise SaaS, crypto holdings, and messenger-platform takeover.
Storm represents the productisation of a technique that researchers have warned about for two years: once session cookies are in attacker hands, MFA is no longer a control. Defenders must shift from credential-centric monitoring toward session-integrity monitoring (anomalous user-agent, ASN, geolocation, concurrent session signals) and hardened browser telemetry capable of detecting raw-database exfiltration patterns even when decryption never happens on-host.
MITRE ATT&CK techniques used in TL-2026-0355
Collection
T1005 Data from Local System; T1074.001 Data Staged: Local Data Staging; T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Credential Access
T1056 Input Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers; T1606 Forge Web Credentials
Execution
T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1106 Native API
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1090.003 Proxy: Multi-hop Proxy; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery
Impact
T1531 Account Access Removal; T1657 Financial Theft
Resource Development
T1583.003 Acquire Infrastructure: Virtual Private Server; T1588.001 Obtain Capabilities: Malware
defense-impairment
Affected products and versions in Storm Infostealer (v0.0.2.0 Gunnar)
- Google — Chrome (and Chromium-based browsers)
Vulnerable versions: All versions — App-Bound Encryption does not prevent raw encrypted store exfiltration - Mozilla — Firefox
Vulnerable versions: All versions - Waterfox Limited — Waterfox
Vulnerable versions: All versions - Moonchild Productions — Pale Moon
Vulnerable versions: All versions - Microsoft — Entra ID / Microsoft 365 (session token reuse)
Vulnerable versions: All tenants without CAE + device-bound conditional access - Google — Google Workspace / Google Account (refresh token replay)
Vulnerable versions: All tenants without device-bound context-aware access - Telegram / Signal / Discord — Desktop client session stores
Vulnerable versions: All versions - Coinbase / Binance / Blockchain.com / Crypto.com — Browser extension and desktop wallet clients
Vulnerable versions: All versions
Remediation for Storm Infostealer (v0.0.2.0 Gunnar)
Patches
- Chrome App-Bound Encryption (Chrome 127, July 2024) mitigates local decryption but does NOT mitigate raw encrypted file exfiltration; it must be combined with EDR file-access monitoring
- Ensure Chromium browsers are updated to the latest stable channel so App-Bound Encryption key material is rotated on each profile migration
Immediate actions
- Invalidate all active browser sessions for users with suspected infections; force full re-authentication and refresh token revocation across Google Workspace, Microsoft 365/Entra ID, Okta, and other SaaS IdPs
- Rotate saved browser passwords and crypto wallet seeds for any host with indicators of raw Login Data / Cookies database access
- Block egress to unknown VPS ranges from endpoint subnets where technically feasible; prioritize outbound HTTPS anomaly detection on short-lived sessions transferring >1 MB of binary data from user profile paths
- Hunt for PowerShell loaders launched with -exec bypass executing .ps1 payloads that touch Chrome User Data or Firefox profile directories within 5 minutes of launch
- Wipe and reimage confirmed infected Windows endpoints; do not attempt in-place cleanup — stealers with file grabbers have already exfiltrated document corpora
Workarounds
- Restrict local admin and reduce persistent logins to sensitive SaaS tenants from user workstations; require step-up authentication for admin consoles
- For high-risk roles (finance, IT admin, crypto custody) issue dedicated managed browsers or virtualized browser sessions that are wiped between sessions
Longer-term hardening
- Deploy conditional access policies that bind Azure Entra ID / Google sessions to device compliance, IP reputation, and ASN anomaly signals so that stolen refresh tokens replayed from attacker SOCKS5 proxies are blocked at authentication
- Enable Continuous Access Evaluation (CAE) and short-lived session token lifetimes across all critical SaaS IdPs
- Deploy EDR with behavioral detection for raw access to Chromium Login Data, Cookies, and Local State files by non-browser processes, and for exfiltration of those files over HTTPS
- Deploy a DNS/URL filtering layer capable of blocking newly-registered domains and low-reputation VPS infrastructure common to MaaS infostealer operators
- Adopt FIDO2/WebAuthn (passkeys) for privileged SaaS access — hardware-bound credentials cannot be replayed from stolen cookies
- Establish a session hijack detection program that monitors concurrent session anomalies (impossible travel, user-agent divergence, token rebind events)
Weaknesses (CWE) in Storm Infostealer (v0.0.2.0 Gunnar)
Timeline of Storm Infostealer (v0.0.2.0 Gunnar)
- Google ships App-Bound Encryption in Chrome 127, raising the bar on local Chromium cookie/credential decryption and invalidating a generation of infostealer tradecraft.
- Varonis Threat Labs publishes Cookie-Bite research demonstrating that stolen Microsoft Entra ID session cookies completely bypass MFA — a foundational result later productised by Storm.
- Underground forum account ''StormStealer'' (forum ID 221756) is registered and begins advertising the Storm Infostealer Malware-as-a-Service.
- First operator subscriptions go live; early victim telemetry begins accruing in the central panel across multiple geographies.
- Storm v0.0.2.0 ''Gunnar'' build circulated to subscribers, adding server-side Gecko (Firefox/Waterfox/Pale Moon) decryption support alongside existing Chromium handling.
- Varonis Threat Labs completes panel reconnaissance, documenting 1,715 victim log entries in the live operator panel across India, US, Brazil, Indonesia, Ecuador, and Vietnam.
- Threadlinqs Intelligence ingests Storm as TL-2026-0355 and kicks off the detection and simulation pipeline.
- Varonis publishes the Storm Infostealer writeup; BleepingComputer, Infosecurity Magazine, HackRead, and SC Media cover the disclosure.
- As of 2026-05-29, Storm Infostealer remains an active commercial MaaS (disclosed by Varonis 2026-04-13, ~1,715 live victims), still sold underground with no takedown, arrest, or successor reported. Its server-side decryption defeats Chrome App-Bound Encryption with no on-host patch possible, and the Cookie Restoration Panel still bypasses MFA via stolen refresh tokens.
Sources cited for Storm Infostealer (v0.0.2.0 Gunnar)
- Varonis Threat Labs: A Quiet Storm — Infostealer Hijacks Sessions, Decrypts Server-Side
- BleepingComputer: The silent Storm — New infostealer hijacks sessions, decrypts server-side
- Infosecurity Magazine: New Storm Infostealer Remotely Decrypts Stolen Credentials
- HackRead: Storm Infostealer Sold as Service, Targets Browsers, Wallets and Accounts
- SC Media: Storm infostealer bypasses Chrome encryption, targets crypto wallets
- Varonis Research: Cookie-Bite — Stolen Entra ID Session Cookies Bypass MFA
- Google Security Blog: App-Bound Encryption in Chrome 127
- MITRE ATT&CK: T1539 Steal Web Session Cookie
- MITRE ATT&CK: T1555.003 Credentials from Web Browsers
Detection coverage for TL-2026-0355
As of 2026-04-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0355 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.