StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware. It is primarily designed to harvest credentials and other sensitive data from infected systems, including browser-stored information and, in observed derivative use, financial credentials and cryptocurrency wallet data. StormKitty has also been used as a building block inside broader malware ecosystems, with multiple stealers and loaders incorporating or forking its code.
StormKitty is frequently associated with Telegram-based data theft workflows and has appeared alongside or inside campaigns involving other commodity malware such as AsyncRAT, VenomRAT, Vidar, RedLine, LummaStealer, and related stealers. Security reporting has identified StormKitty code reuse in families including BlackGuard, BluStealer, Prynt Stealer, and other custom stealers, indicating that it has served as a readily available source of credential-theft and exfiltration functionality for criminal operators.
Observed delivery and deployment contexts show StormKitty being distributed on Windows through trojanized software installers, including cracked or fake software packages, and as a payload dropped by loaders. In some campaigns it has been bundled with additional malware families and launched through process hollowing or similar injection-based execution chains. StormKitty has also been observed as a customized payload loaded by other malware during post-compromise activity.
Its role in the threat landscape is best understood as a commodity infostealer family and codebase rather than a single tightly controlled operation. The malware is notable both for direct credential theft and for its influence on later stealers that inherited its Telegram exfiltration logic, browser data theft routines, and broader information-harvesting behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Process Injection (T1055.012): CreateProcessAsUserW → Create suspended target process; WriteProcessMemory → Write payload into target address space; SetThreadContext → Redirect execution to payload entry point; ResumeThread → Resume execution under target process identity
Process Injection (T1055.012): CreateProcessAsUserW → Create suspended target process; WriteProcessMemory → Write payload into target address space; SetThreadContext → Redirect execution to payload entry point; ResumeThread → Resume execution under target process identity
The malware establishes a connection to the pastebin website ... to obtain the IP address and port number of the C2 ... It then initiates a connection to the C2 server
Le principe : un token bot et un chat_id embarqués dans le binaire permettent d’envoyer les données volées directement dans un chat Telegram via api.telegram.org.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer malware listed among malware/tools observed in the Telegram malware ecosystem.
A stealer family observed sharing the same Russian-hosted multi-family C2 infrastructure.
Stealer payload delivered by the Golang 'Birkenhead' loader together with VenomRAT and Vidar. The content states it exfiltrates Discord tokens, browser data, and keylogging data.
Commodity stealer added to Infy’s toolkit during its expanded operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.