Skip to content

StormKitty

StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware.

Profile source: Mallory opens in a new tab

StormKitty

Family profile

StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware. It is primarily designed to harvest credentials and other sensitive data from infected systems, including browser-stored information and, in observed derivative use, financial credentials and cryptocurrency wallet data. StormKitty has also been used as a building block inside broader malware ecosystems, with multiple stealers and loaders incorporating or forking its code.

StormKitty is frequently associated with Telegram-based data theft workflows and has appeared alongside or inside campaigns involving other commodity malware such as AsyncRAT, VenomRAT, Vidar, RedLine, LummaStealer, and related stealers. Security reporting has identified StormKitty code reuse in families including BlackGuard, BluStealer, Prynt Stealer, and other custom stealers, indicating that it has served as a readily available source of credential-theft and exfiltration functionality for criminal operators.

Observed delivery and deployment contexts show StormKitty being distributed on Windows through trojanized software installers, including cracked or fake software packages, and as a payload dropped by loaders. In some campaigns it has been bundled with additional malware families and launched through process hollowing or similar injection-based execution chains. StormKitty has also been observed as a customized payload loaded by other malware during post-compromise activity.

Its role in the threat landscape is best understood as a commodity infostealer family and codebase rather than a single tightly controlled operation. The malware is notable both for direct credential theft and for its influence on later stealers that inherited its Telegram exfiltration logic, browser data theft routines, and broader information-harvesting behavior.

Capabilities

  • Credential Theft
  • Exfiltration

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 24, 2026
Last activity
Sep 28, 2026
Feed role
C2 / Distribution
Host form
6 IP / 3 hostnames

Leading locations

  • DE4
  • FI1
  • GR1
  • KR1
  • NL1
  • RU1

Leading providers

  • FEMO IT SOLUTIONS LIMITED2
  • Hetzner Online GmbH1
  • HOSTMEIN IKE1
  • JSC IOT1
  • Netiface America, Inc.1
  • Omegatech LTD1

Infrastructure traits

  • Hosting 8

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Prince of Persia

The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...

MITRE ATT&CK

StormKitty in ATT&CK

16 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.