New Password Stealer Bypasses 2FA—Chrome, Edge And Firefox Targeted

TL;DR AI
2 min readKey summary
Researchers at Varonis Threat Labs confirmed Storm, a new infostealer-for-hire that targets Chrome, Edge and Firefox.
Storm can steal browser passwords, session cookies, payment card data, documents, messaging session data, and crypto wallet information.
The service lets operators restore hijacked sessions to bypass two-factor authentication and is rentable for about $1,000 per month.
Operators route stolen data through their own VPS nodes and use an operator panel to automate session restoration.



