Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS Sessions — Threadlinqs Intelligence
As of 2026-05-30, Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS Sessions is a high-severity malware threat attributed to StormStealer (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-0355 · Severity: HIGH · CVSS: 8.1 · Status: ACTIVE · Category: MALWARE
Attribution: StormStealer · Russia · FINANCIAL
Storm is a C++ Windows infostealer sold as a subscription service on underground forums that bypasses Chrome's App-Bound Encryption (introduced July 2024) by shipping raw encrypted browser databases,
Storm Infostealer is a Malware-as-a-Service credential theft platform first surfaced on underground cybercrime forums on December 12, 2025 under the seller handle ''StormStealer'' (forum ID 221756) and publicly disclosed by Varonis Threat Labs in April 2026. The current build, v0.0.2.0 codename ''Gunnar'', is a ~460 KB C++ (MSVC/msbuild) Windows-only binary that operates almost entirely in memory to reduce host telemetry.
Storm''s defining innovation is its rejection of local credential decryption. Prior-generation stealers (RedLine, StealC, Raccoon, Lumma) loaded SQLite at runtime against Chromium ''Login Data'' and ''Cookies'' stores and invoked DPAPI/CryptUnprotectData or Chrome''s app-bound decryption routines on the victim host — activity that EDR and endpoint DLP products have learned to hook and alert on. Storm instead copies the raw encrypted SQLite databases, the App-Bound-Encrypted key material, and Firefox/Gecko credential vaults (targeting Waterfox and Pale Moon in addition to mainline Firefox) and exfiltrates them wholesale to operator-controlled VPS infrastructure. Decryption is performed server-side on hardware outside the defender''s visibility, completely sidestepping Chrome 127''s App-Bound Encryption mitigation that Google shipped in July 2024.
Collection scope is broad: saved passwords, session cookies, autofill forms, credit-card records, Google account tokens, browsing history, Telegram/Signal/Discord session blobs, crypto wallet files from both browser extensions and desktop applications (Coinbase, Binance, Blockchain.com, Crypto.com), a configurable file grabber that sweeps user document directories, system information fingerprints, and multi-monitor GDI screen captures. Data is processed in memory and staged before exfiltration over the C2 channel.
Storm''s operator backend, the Cookie Restoration Panel, is the feature that transforms raw stolen cookies into live SaaS compromise. An operator supplies a harvested Google Refresh Token (or equivalent session artifact) together with a SOCKS5 proxy selected to match the victim''s geographic origin, and the panel silently rehydrates an authenticated browser session. Because the session was established before MFA, password changes, refresh-token rotation, and conditional access policies gated on location do not trigger. Varonis explicitly ties this workflow to its prior Cookie-Bite and SessionShark research, which demonstrated that stolen Azure Entra ID session cookies completely bypass MFA on Microsoft 365 and Azure tenants. A single compromised employee browser can therefore hand an operator authenticated access to SaaS platforms, internal admin consoles, and cloud tenants without triggering a single password-based alert.
Operator infrastructure is deliberately layered to defeat takedown: affiliates connect personal VPNs into Storm''s central servers, and stolen data routes through the operator''s own VPS node first so that abuse complaints and subpoenas land on disposable infrastructure while the central collection server remains insulated. The platform supports team management with role-based permissions (targeting organised criminal crews) and auto-classifies stolen credentials by service domain (Google, Facebook, Twitter/X, cPanel).
Commercial terms are aggressive: $300 for a 7-day demo, $900/month for a standard license, and $1,800/month for a team license that provides 100 concurrent worker seats and 200 builds; a separate crypter must be procured by the buyer. Critically, builds keep running after a subscription lapses — harvested data continues to be shipped to operator infrastructure regardless of license status, producing long-tail collection from abandoned campaigns.
Evidence of active exploitation is unambiguous. At the time of Varonis''s investigation the panel held 1,715 distinct victim log entries spanning India, the United States, Brazil, Indonesia, Ecuador, Vietnam, and other countries, with varied IP ranges, ISPs, and data volumes th
Weaknesses (CWE)
CWE-522, CWE-311, CWE-312, CWE-384, CWE-613
Target sectors: enterprise SaaS tenants, financial services, cryptocurrency, technology, hosting / cPanel operators, social media users, small and medium business
Target regions: India, United States, Brazil, Indonesia, Ecuador, Vietnam, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1059, T1059.001, T1106, T1027, T1070, T1562, T1620, T1555, T1555.003, T1539