Storm Infostealer: Your Browser Sessions Are Now for Sale, Undetected
Imagine logging into your corporate email, only for a cybercrook halfway across the world to slip in behind you—using your own active session. Storm's doing exactly that, and it's dirt cheap.
CVE WatchApr 12, 20264 min read
⚡ Key Takeaways
Storm decrypts stolen browser data server-side, dodging endpoint detection tools.𝕏
Automated session hijacking bypasses MFA, enabling passwordless access to SaaS and cloud tools.𝕏
Sold as cheap SaaS ($900/month), it's fueling account takeovers worldwide with 1,700+ active logs.𝕏
The 60-Second TL;DR
Storm decrypts stolen browser data server-side, dodging endpoint detection tools.
Automated session hijacking bypasses MFA, enabling passwordless access to SaaS and cloud tools.
Sold as cheap SaaS ($900/month), it's fueling account takeovers worldwide with 1,700+ active logs.