Last seven days
- First activity
- Sep 24, 2026
- Last activity
- Sep 28, 2026
- Feed role
- C2 / Distribution
- Host form
- 6 IP / 3 hostnames
StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware.
Profile source: Mallory opens in a new tabStormKitty
StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware. It is primarily designed to harvest credentials and other sensitive data from infected systems, including browser-stored information and, in observed derivative use, financial credentials and cryptocurrency wallet data. StormKitty has also been used as a building block inside broader malware ecosystems, with multiple stealers and loaders incorporating or forking its code.
StormKitty is frequently associated with Telegram-based data theft workflows and has appeared alongside or inside campaigns involving other commodity malware such as AsyncRAT, VenomRAT, Vidar, RedLine, LummaStealer, and related stealers. Security reporting has identified StormKitty code reuse in families including BlackGuard, BluStealer, Prynt Stealer, and other custom stealers, indicating that it has served as a readily available source of credential-theft and exfiltration functionality for criminal operators.
Observed delivery and deployment contexts show StormKitty being distributed on Windows through trojanized software installers, including cracked or fake software packages, and as a payload dropped by loaders. In some campaigns it has been bundled with additional malware families and launched through process hollowing or similar injection-based execution chains. StormKitty has also been observed as a customized payload loaded by other malware during post-compromise activity.
Its role in the threat landscape is best understood as a commodity infostealer family and codebase rather than a single tightly controlled operation. The malware is notable both for direct credential theft and for its influence on later stealers that inherited its Telegram exfiltration logic, browser data theft routines, and broader information-harvesting behavior.
C2 tracking
Derp observations, rolling seven-day window
Samples
44593e8065a0f6c19d3a8fe2c49f13d1d202c2f78cf8a6157e01ca6d15164298 68130e5ff74c361cf84743a48d9da067b126a90f09d11cf64a322b1dfe2c9900 7c89b46538bd83a42a8ce07f7c97ab6028ec153cf649d89776b6f15071b08618 a2fa794887ecb96a4b40389fe152e52707c021c86f63c4430557e7c286840b96 add81f5674192bcc725624fad7805d9640a1ddbd285d4c371b21a21e1e5d6234 046c4924818902ea213e2077a7257eeadb388ac3682be1c6621274c2cab45bf2 0dedb6c88372665e78cbba37624d0431c2171c6d932c6a8bcbe54b3c7d5bba33 3118a029c644a831c1ae3e55047b2598462c70c45053425d985de24c22b04eb1 87f650c45d935e3113505230e69cf7c7e9cf51a60ab5b053d3fc373fce4a2704 a6a1598cd6713d7afbfc6d48427dd986154aa724215549477f190d10ee15bfe2 Reported operators
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.