Skip to content
Malware family

StormKitty

StormKitty is an information-stealing malware family focused on harvesting financial credentials and cryptocurrency wallet data.

Profile source: Mallory opens in a new tab

StormKitty

Family profile

StormKitty is an information-stealing malware family focused on harvesting financial credentials and cryptocurrency wallet data. The provided reporting explicitly describes it as an infostealer and notes that code from StormKitty was reused in other malware, including Prynt Stealer, where Telegram exfiltration functionality was copied from StormKitty with minor modifications. StormKitty has also appeared as part of multi-malware delivery chains and shared infrastructure: a Golang loader identified as Birkenhead was reported to drop StormKitty, VenomRAT, and Vidar simultaneously using process hollowing, and StormKitty was linked to the multi-family C2 server 178.22.24.175 in Russian ASN AS209290 alongside VenomRAT, Vidar, QuasarRAT/AsyncRAT, RedLine, and other malware hosted in the same broader cluster. Additional reporting states that a fake Bitdefender website distributed StormKitty together with VenomRAT and SilentTrinity, and that another campaign toolkit incorporated commodity malware including Remcos RAT, Stealerium, StormKitty, and ZZ Stealer. SafeBreach also reported that ZZ Stealer loaded a fork of the StormKitty infostealer. High-confidence infrastructure and campaign details directly mentioned in the content include the association of StormKitty with 178.22.24.175 and its use in bundled or staged malware operations targeting Windows systems through trojanized installers, fake software sites, and loader-based deployment.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
5 IP / 4 hostnames

Leading locations

  • US3
  • DE1
  • FI1
  • FR1
  • HK1
  • NL1
  • RU1

Leading providers

  • Cloudflare, Inc.2
  • AEZA GROUP LLC1
  • Evoxt Sdn. Bhd.1
  • FEMO IT SOLUTIONS LIMITED1
  • GTHost1
  • Hetzner Online GmbH1

Infrastructure traits

  • Hosting 9
  • Anycast 2

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Prince of Persia

The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...

MITRE ATT&CK

StormKitty in ATT&CK

6 distinct techniques

Reporting

Research mentioning StormKitty

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.