Skip to content

StormKitty

StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware.

Profile source: Mallory opens in a new tab

StormKitty

Family profile

StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware. It is primarily designed to harvest credentials and other sensitive data from infected systems, including browser-stored information and, in observed derivative use, financial credentials and cryptocurrency wallet data. StormKitty has also been used as a building block inside broader malware ecosystems, with multiple stealers and loaders incorporating or forking its code.

StormKitty is frequently associated with Telegram-based data theft workflows and has appeared alongside or inside campaigns involving other commodity malware such as AsyncRAT, VenomRAT, Vidar, RedLine, LummaStealer, and related stealers. Security reporting has identified StormKitty code reuse in families including BlackGuard, BluStealer, Prynt Stealer, and other custom stealers, indicating that it has served as a readily available source of credential-theft and exfiltration functionality for criminal operators.

Observed delivery and deployment contexts show StormKitty being distributed on Windows through trojanized software installers, including cracked or fake software packages, and as a payload dropped by loaders. In some campaigns it has been bundled with additional malware families and launched through process hollowing or similar injection-based execution chains. StormKitty has also been observed as a customized payload loaded by other malware during post-compromise activity.

Its role in the threat landscape is best understood as a commodity infostealer family and codebase rather than a single tightly controlled operation. The malware is notable both for direct credential theft and for its influence on later stealers that inherited its Telegram exfiltration logic, browser data theft routines, and broader information-harvesting behavior.

Capabilities

  • Credential Theft
  • Exfiltration

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 9, 2026
Last activity
Aug 16, 2026
Feed role
C2 / Distribution
Host form
13 IP / 4 hostnames

Leading locations

  • US4
  • DE3
  • HK3
  • NL3
  • CA1
  • PL1
  • SI1

Leading providers

  • Cloudie Limited2
  • FEMO IT SOLUTIONS LIMITED2
  • NetCrafters OU2
  • Omegatech LTD2
  • Cloudflare, Inc.1
  • Emil Vitukhnovskii trading as Great Flower1

Infrastructure traits

  • Hosting 16
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Prince of Persia

The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...

MITRE ATT&CK

StormKitty in ATT&CK

16 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.