Switch language한국어
Back to the list

New Password Stealer Bypasses 2FA—Chrome, Edge And Firefox Targeted

TL;DR AI

Key summary

2 min read
  1. Researchers at Varonis Threat Labs identified a new infostealer called Storm that targets Chrome, Edge and Firefox.

  2. Storm moves encrypted browser data to its servers, decrypts credentials and session cookies, and delivers them to an operator panel.

  3. Operators can restore hijacked sessions by supplying stolen tokens and geographically matched SOCKS5 proxies, enabling 2FA bypass and account takeover.

  4. Storm is offered for rent to cybercriminals for about $1,000 per month and can be used to access SaaS, internal tools, and cloud resources.

Read the original