Last seven days
- First activity
- Aug 9, 2026
- Last activity
- Aug 16, 2026
- Feed role
- C2 / Distribution
- Host form
- 13 IP / 4 hostnames
StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware.
Profile source: Mallory opens in a new tabStormKitty
StormKitty is a Windows information-stealing malware family implemented in .NET and widely referenced as an open-source or leaked stealer codebase reused by other commodity malware. It is primarily designed to harvest credentials and other sensitive data from infected systems, including browser-stored information and, in observed derivative use, financial credentials and cryptocurrency wallet data. StormKitty has also been used as a building block inside broader malware ecosystems, with multiple stealers and loaders incorporating or forking its code.
StormKitty is frequently associated with Telegram-based data theft workflows and has appeared alongside or inside campaigns involving other commodity malware such as AsyncRAT, VenomRAT, Vidar, RedLine, LummaStealer, and related stealers. Security reporting has identified StormKitty code reuse in families including BlackGuard, BluStealer, Prynt Stealer, and other custom stealers, indicating that it has served as a readily available source of credential-theft and exfiltration functionality for criminal operators.
Observed delivery and deployment contexts show StormKitty being distributed on Windows through trojanized software installers, including cracked or fake software packages, and as a payload dropped by loaders. In some campaigns it has been bundled with additional malware families and launched through process hollowing or similar injection-based execution chains. StormKitty has also been observed as a customized payload loaded by other malware during post-compromise activity.
Its role in the threat landscape is best understood as a commodity infostealer family and codebase rather than a single tightly controlled operation. The malware is notable both for direct credential theft and for its influence on later stealers that inherited its Telegram exfiltration logic, browser data theft routines, and broader information-harvesting behavior.
C2 tracking
Derp observations, rolling seven-day window
Samples
1066003052bf79de8ab4f07bb7ff3dc980a8622b9175ef714a6df5dd01d517b7 155d1dce8e17b107b531b80b648f1a3fcbcbed764d76a39b0b3972d9424dd2f7 34269d04e2b98d72ec70d2b7f55d57c95fb50702bfc17dca49b80f1908202e8d 84b8ec2f3b29a10f88d21fc7617cdfecac1c2c76303086b41471beb5f563f65c c767bb6b6dd0b149e46b7066269b6d9fac1f9eb2dcafcec59475fd78a8af7861 1b71e681d2a70a4358cee8ed8d5787d3b0623320e338f1e55f21c4b79e2f1aaa 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 32ead15908ca61088701ec6ee4c692658585746bafb52cce23c047d035fc91a5 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 a835f1601b2834fbeb9a3b4b3156d0d0e5ddeac3d9ca0500f5cbfe832d6958b4 Reported operators
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.