Storm Stealer Hijacks Browser Sessions, Bypasses 2FA

Storm infostealer, confirmed April 6, 2026, targets major browsers to steal passwords and sessions, enabling 2FA bypass and wider data theft.

Jason Kwon ·

Storm Stealer Hijacks Browser Sessions, Bypasses 2FA

Varonis Threat Labs researchers confirmed on April 6, 2026, the emergence of “Storm,” a new infostealer platform aimed at users of Google Chrome, Microsoft Edge, and Mozilla Firefox. Officials described the tool as designed to pull passwords and session data, which can allow attackers to bypass two-factor authentication (2FA) and reach sensitive accounts and information.

According to the researchers, Storm’s core technique centers on browser credentials and session cookies. Rather than relying on the victim’s device to decrypt stolen data, Storm remotely decrypts browser credentials and session cookies after moving encrypted files off the endpoint. The researchers said this workflow can evade traditional endpoint security tools that are built to detect suspicious local access to browser databases.

The researchers contrasted Storm with earlier infostealers that performed decryption on the compromised machine. In Storm’s model, encrypted browser files are transferred to an attacker-controlled server for decryption. The stated effect is to reduce the likelihood of triggering security software that flags local database access attempts, while still enabling account takeover through captured sessions and credentials.

Varonis Threat Labs also reported that Storm is offered as a rental service to cybercriminals for approximately $1,000 per month. Beyond browser data, the platform is described as capable of extracting documents from user directories and collecting session data from messaging applications including Telegram, Signal, and Discord. The researchers said it also targets cryptocurrency wallets through both browser extensions and desktop applications.

The tool’s capabilities extend to broader device surveillance and profiling, the researchers said. Storm captures system information and takes screenshots across multiple monitors, expanding the range of data that can be stolen from a compromised machine. Taken together, the reported feature set positions Storm as a multi-purpose theft platform rather than a narrow credential grabber.

For global markets and politics, the report underscores how widely used consumer and enterprise browsers can become a common entry point for credential theft and session hijacking. The researchers’ description highlights a key uncertainty for defenders: endpoint controls tuned to detect on-device decryption and local database access may not reliably surface threats that shift sensitive processing to remote infrastructure.

Varonis Threat Labs did not describe the scale of infections or specific victim geographies in the confirmation.

More stories