Last seven days
- First activity
- Jul 19, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 4 hostnames
StormKitty is an information-stealing malware family focused on harvesting financial credentials and cryptocurrency wallet data.
Profile source: Mallory opens in a new tabStormKitty
StormKitty is an information-stealing malware family focused on harvesting financial credentials and cryptocurrency wallet data. The provided reporting explicitly describes it as an infostealer and notes that code from StormKitty was reused in other malware, including Prynt Stealer, where Telegram exfiltration functionality was copied from StormKitty with minor modifications. StormKitty has also appeared as part of multi-malware delivery chains and shared infrastructure: a Golang loader identified as Birkenhead was reported to drop StormKitty, VenomRAT, and Vidar simultaneously using process hollowing, and StormKitty was linked to the multi-family C2 server 178.22.24.175 in Russian ASN AS209290 alongside VenomRAT, Vidar, QuasarRAT/AsyncRAT, RedLine, and other malware hosted in the same broader cluster. Additional reporting states that a fake Bitdefender website distributed StormKitty together with VenomRAT and SilentTrinity, and that another campaign toolkit incorporated commodity malware including Remcos RAT, Stealerium, StormKitty, and ZZ Stealer. SafeBreach also reported that ZZ Stealer loaded a fork of the StormKitty infostealer. High-confidence infrastructure and campaign details directly mentioned in the content include the association of StormKitty with 178.22.24.175 and its use in bundled or staged malware operations targeting Windows systems through trojanized installers, fake software sites, and loader-based deployment.
C2 tracking
Derp observations, rolling seven-day window
Samples
b744ab8e1f5b87327281e9c6559c8f8d460439c054dd3783ed395137fcae8064 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac 8aa30391aef3ffd2d5cdd93e76aa66a8ad5075adc22dd235882cf206b28c7f1f c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861 e74456a7f7a68b46a907f8ed737aeac6b90cdf660affd32136152a94a47400b6 03a3b3b2a9a5589a715f18c7d9e190d38ec7b55a4f58ecdc9842522060f8f03e 155d1dce8e17b107b531b80b648f1a3fcbcbed764d76a39b0b3972d9424dd2f7 89de93e69e898d5da92c572f472fc8d0b3b1162eb8d98d4790d2fd6ff849de5b e6e448215af5a4f173a89a0c9f829d6abf3fce275af2317310c3bb448a0c35ad Reported operators
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
MITRE ATT&CK
Reporting
VenomRAT Multi-Family C2: 178.22.24.175 (Russia) ... Families VenomRAT, Vidar, StormKitty, LummaStealer, RedLine
The Birkenhead Loader (StormKitty/VenomRAT/Vidar) ... It is a Golang-compiled process hollowing loader that drops all three payloads simultaneously.
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
"...ZZ Stealer...loads a fork of the StormKitty infostealer..."
StormKitty hunts for financial credentials and crypto wallets, while SilentTrinity maintains persistent backdoor access.
The Prynt Stealer code is primarily derived from AsyncRAT (a versatile RAT) and StormKitty (an information stealer).
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.