# Storm Infostealer (v0.0.2.0 Gunnar): Server-Side Browser Decryption Bypasses Chrome App-Bound Encryption and Hijacks MFA-Protected SaaS Sessions

> Storm is a C++ Windows infostealer sold as a subscription service on underground forums that bypasses Chrome's App-Bound Encryption (introduced July 2024) by shipping raw encrypted browser databases, cookies, autofill, and wallet files to attacker-controlled infrastructure where decryption is performed server-side. A built-in Cookie Restoration Panel uses Google Refresh Tokens routed through geographically matched SOCKS5 proxies to silently resume authenticated SaaS sessions, rendering password and MFA controls irrelevant. Varonis Threat Labs disclosed 1,715 victim log entries in the operator panel spanning India, US, Brazil, Indonesia, Ecuador, and Vietnam at the time of analysis, indicating an active global campaign.

- **Published:** 2026-04-13T12:00:00Z
- **Last reviewed:** 2026-04-13T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0355
- **ID:** TL-2026-0355
- **Severity:** HIGH (CVSS 8.1)
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** StormStealer (Russia)
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Storm Infostealer is a Malware-as-a-Service credential theft platform first surfaced on underground cybercrime forums on December 12, 2025 under the seller handle ''StormStealer'' (forum ID 221756) and publicly disclosed by Varonis Threat Labs in April 2026. The current build, v0.0.2.0 codename ''Gunnar'', is a ~460 KB C++ (MSVC/msbuild) Windows-only binary that operates almost entirely in memory to reduce host telemetry.

Storm''s defining innovation is its rejection of local credential decryption. Prior-generation stealers (RedLine, StealC, Raccoon, Lumma) loaded SQLite at runtime against Chromium ''Login Data'' and ''Cookies'' stores and invoked DPAPI/CryptUnprotectData or Chrome''s app-bound decryption routines on the victim host — activity that EDR and endpoint DLP products have learned to hook and alert on. Storm instead copies the raw encrypted SQLite databases, the App-Bound-Encrypted key material, and Firefox/Gecko credential vaults (targeting Waterfox and Pale Moon in addition to mainline Firefox) and exfiltrates them wholesale to operator-controlled VPS infrastructure. Decryption is performed server-side on hardware outside the defender''s visibility, completely sidestepping Chrome 127''s App-Bound Encryption mitigation that Google shipped in July 2024.

Collection scope is broad: saved passwords, session cookies, autofill forms, credit-card records, Google account tokens, browsing history, Telegram/Signal/Discord session blobs, crypto wallet files from both browser extensions and desktop applications (Coinbase, Binance, Blockchain.com, Crypto.com), a configurable file grabber that sweeps user document directories, system information fingerprints, and multi-monitor GDI screen captures. Data is processed in memory and staged before exfiltration over the C2 channel.

Storm''s operator backend, the Cookie Restoration Panel, is the feature that transforms raw stolen cookies into live SaaS compromise. An operator supplies a harvested Google Refresh Token (or equivalent session artifact) together with a SOCKS5 proxy selected to match the victim''s geographic origin, and the panel silently rehydrates an authenticated browser session. Because the session was established before MFA, password changes, refresh-token rotation, and conditional access policies gated on location do not trigger. Varonis explicitly ties this workflow to its prior Cookie-Bite and SessionShark research, which demonstrated that stolen Azure Entra ID session cookies completely bypass MFA on Microsoft 365 and Azure tenants. A single compromised employee browser can therefore hand an operator authenticated access to SaaS platforms, internal admin consoles, and cloud tenants without triggering a single password-based alert.

Operator infrastructure is deliberately layered to defeat takedown: affiliates connect personal VPNs into Storm''s central servers, and stolen data routes through the operator''s own VPS node first so that abuse complaints and subpoenas land on disposable infrastructure while the central collection server remains insulated. The platform supports team management with role-based permissions (targeting organised criminal crews) and auto-classifies stolen credentials by service domain (Google, Facebook, Twitter/X, cPanel).

Commercial terms are aggressive: $300 for a 7-day demo, $900/month for a standard license, and $1,800/month for a team license that provides 100 concurrent worker seats and 200 builds; a separate crypter must be procured by the buyer. Critically, builds keep running after a subscription lapses — harvested data continues to be shipped to operator infrastructure regardless of license status, producing long-tail collection from abandoned campaigns.

Evidence of active exploitation is unambiguous. At the time of Varonis''s investigation the panel held 1,715 distinct victim log entries spanning India, the United States, Brazil, Indonesia, Ecuador, Vietnam, and other countries, with varied IP ranges, ISPs, and data volumes that are inconsistent with test telemetry. No nation-state attribution has been made; the platform appears to be financially motivated eCrime targeting enterprise SaaS, crypto holdings, and messenger-platform takeover.

Storm represents the productisation of a technique that researchers have warned about for two years: once session cookies are in attacker hands, MFA is no longer a control. Defenders must shift from credential-centric monitoring toward session-integrity monitoring (anomalous user-agent, ASN, geolocation, concurrent session signals) and hardened browser telemetry capable of detecting raw-database exfiltration patterns even when decryption never happens on-host.

## MITRE ATT&CK

- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1106 Native API
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1685 Disable or Modify Tools
- T1620 Reflective Code Loading
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1552.001 Unsecured Credentials: Credentials In Files
- T1528 Steal Application Access Token
- T1606 Forge Web Credentials
- T1056 Input Capture
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1217 Browser Information Discovery
- T1005 Data from Local System
- T1113 Screen Capture
- T1115 Clipboard Data
- T1119 Automated Collection
- T1074.001 Data Staged: Local Data Staging
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1090.003 Proxy: Multi-hop Proxy
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1531 Account Access Removal
- T1657 Financial Theft
- T1588.001 Obtain Capabilities: Malware
- T1583.003 Acquire Infrastructure: Virtual Private Server

## Sources

- [Varonis Threat Labs: A Quiet Storm — Infostealer Hijacks Sessions, Decrypts Server-Side](https://www.varonis.com/blog/storm-infostealer)
- [BleepingComputer: The silent Storm — New infostealer hijacks sessions, decrypts server-side](https://www.bleepingcomputer.com/news/security/the-silent-storm-new-infostealer-hijacks-sessions-decrypts-server-side/)
- [Infosecurity Magazine: New Storm Infostealer Remotely Decrypts Stolen Credentials](https://www.infosecurity-magazine.com/news/storm-infostealer-remotely/)
- [HackRead: Storm Infostealer Sold as Service, Targets Browsers, Wallets and Accounts](https://hackread.com/storm-infostealer-sold-as-service-browsers-wallets/)
- [SC Media: Storm infostealer bypasses Chrome encryption, targets crypto wallets](https://www.scworld.com/brief/storm-infostealer-bypasses-chrome-encryption-targets-crypto-wallets)
- [Varonis Research: Cookie-Bite — Stolen Entra ID Session Cookies Bypass MFA](https://www.varonis.com/blog/cookie-bite)
- [Google Security Blog: App-Bound Encryption in Chrome 127](https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html)
- [MITRE ATT&CK: T1539 Steal Web Session Cookie](https://attack.mitre.org/techniques/T1539/)
- [MITRE ATT&CK: T1555.003 Credentials from Web Browsers](https://attack.mitre.org/techniques/T1555/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0355
