This New Tool Can Steal Your Passwords And Info – Even With 2FA Enabled






Newly discovered malware for sale on the black market allows anyone to steal passwords, cryptocurrency, and more from a Windows computer, even with strict security measures enabled. Every time you sigh your way through yet another password field or grumble as you check your phone for a two-factor authentication code, you can take solace in the knowledge that these inconveniences keep your work private and personal data secure. But security is ever-evolving, and no fortress is impenetrable.

The new malware, an infostealer called Storm, was spotted in early 2026, according to a security report by cybersecurity firm Varonis. As you may infer, an infostealer is a piece of software that steals your sensitive personal information and squirrels it away for an attacker. Where Storm differs from other such tools is in its ability to take encrypted information from your browser and decrypt it on a remote server. Think of it like the difference between conducting a bank heist and cracking the safe while you’re still at the scene of the crime versus taking the entire safe home and cracking it open in your basement. In the former scenario, you need to bring your safe-cracking tools inside with you while the seconds tick down until the police arrive. In the latter, you get to work from the comfort of your own home, taking all the time in the world to crack the combination.

Because modern browsers are security-hardened against infostealers that work on an infected device to exfiltrate decrypted data  — they’re very good at detecting those safe-cracking tools, in other words  — Storm has cybersecurity experts raising an eyebrow. Here’s how this new threat works, and why it could spread quickly.

Storm is a new piece of malware that remotely steals and decrypts credentials

Traditional infostealers set up camp in your browser, where they access local SQLite databases and get to work picking your digital locks. Of course, popular browsers like the Chromium project that undergirds Chrome, Edge, and many others have hardened their security against these kinds of attacks. Browsers treat any sign of a database being accessed locally as a massive red flag, effectively siccing the watchdogs on an attacker before they can get away with the goods. Google even deployed a security measure called App-Bound Encryption that tied keys to the browser itself, but hackers quickly made mincemeat of it.

According to Varonis, Storm doesn’t even bother with this locally-bound cat-and-mouse game. Instead, it steals files in an encrypted state. To continue our bank robbery metaphor, imagine the bank’s security is triggered when someone starts meddling with the locks on the safe, but if someone simply loads the safe onto a truck and drives away, the alarm never even goes off. Once safely on the attacker’s server, Storm gets to work cracking encrypted files. It has its own servers, but data is routed through an attacker’s virtual private server, obfuscating Storm’s own infrastructure. By reconstructing the authenticated session after exfiltration, Storm is able to use session cookies to bypass two-factor authentication (2FA) and other modern security measures.

When Storm gets into a system, it can extract passwords, autofill data such as names and addresses, credit card information, browsing history, and so on. It also targets crypto wallets, messaging apps like Discord, Signal, and Telegram, and files from the user’s storage drive. For good measure, it also takes screenshots. The good news, at least for some, is that Storm can only be deployed against Windows systems.

Storm is malware as a subscription service, which could supercharge its reach

Users have grown largely accustomed to software as a service (SaaS), the practice wherein software companies charge an ongoing fee for a product. You pay monthly for things like Spotify, Netflix, or Adobe Photoshop. But what you may not know is that cybercriminals have hopped aboard the SaaS train, too, selling fully operational malware to malicious actors. There was a time when a would-be hacker might be deterred by a simple lack of technical knowledge. These days, even an attacker with very little in the way of coding or networking know-how can simply purchase a fully operational malware suite and commit sophisticated cyber crimes.

Storm is one such example, according to Varonis, and its pricing system reflects the sort of business savvy you’d expect from a legitimate software company, not from a black market cyber-weapons dealer. A week-long demo version of the suite is $300, while a monthly subscription is $900. There’s even an enterprise subscription for $1,800 a month, which authorizes up to 100 operators. But unlike normal subscriptions, Storm will keep harvesting data from compromised sessions even after a subscriber fails to pay their bill. It’s not clear whether the subscriber still gets the looted data collected after their payment lapses.

That kind of accessibility means that a threat like Storm can scale quickly, as threat actors rush to purchase it before browser developers can patch the vulnerabilities it exploits. Concerned Windows users can take some steps to reduce risk. Because Storm can easily bypass 2FA, enable passkeys on all accounts that support them. You should still use 2FA everywhere else. Be on the lookout for logins from strange locations, attempts to change your passwords, and other signs that you’ve been hacked.





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Follow ZDNET: Add us as a preferred source on Google.


It’s officially springtime, which means we’re due for another Amazon Big Spring Sale. Ahead of the deal event, which starts on March 25, several robot vacuums are on sale, including top-end modelds from brands like Ecovacs, Dreame, Roborock, and more. 

Also: I’ve tested dozens of robot vacuums. These are the three I recommend most to family and friends

We’ve tested several of the latest robot vacuums, bringing them into our homes and letting them tackle the messiest of messes from kids, pets, muddy shoes, and more. You can expect more deals on this list as we get closer to the sale, so be sure to check back for updates. In the meantime, these are the best deals you can shop.

Best early Amazon Spring Sale robot vacuum deals

  • Current price: $540 (10% off)
  • Original price: $600

Dreme’s high-end vacuum is over half off its original price, and it’s still one of our favorites. Thanks to its strong 12,000Pa suction, high performance on carpet and hard floors, and exceptional object avoidance, it’s one of the best robot vacuums you can buy.

Review: Dreame X40 Ultra


Show more

  • Current price: $1,100 (31% off)
  • Original price: $1,600

This robot vacuum is adept at navigating complex spaces in your home and mopping hard-to-reach corners. It uses rotating mop pads instead of rollers. 

Review: Roborock Saros 10R


Show more

  • Current price: $1,293 (19% off)
  • Original price: $1,599

If you’re looking for an alternative to mainstream brands, the Mova Mobius 60 delivers. Its intuitive mop features automatically employ one of three mops to properly clean tough stains and messes. 

Review: Mova Mobius 60


Show more

  • Current price: $700 (30% off)
  • Original price: $1,000

This robot vacuum features 20,000Pa suction, intuitive object avoidance, and impressive mopping capabilities. At this sale price, it’s the best time to buy.

Review: Eufy Omni E28


Show more

  • Current price: $679 (48% off)
  • Original price: $1,300

This Ecovacs robot promises 16,600Pa suction, an independent mop, side brush, and main brush lift system, and simultaneous carpet cleaning and drying. 

Review: Ecovacs Deebot X9 Pro Omni


Show more

When is Amazon’s Spring Sale? 

Amazon’s Big Spring Sale begins on Wednesday, March 25, and ends on Tuesday, March 31, 2026. 

How did we choose these early Amazon Spring Sale deals?

ZDNET only writes about deals we want to buy — devices and products we desire, need, or would recommend. We’ve thoroughly tested every robot vacuum on this list, letting them into our homes and tackling life’s biggest messes. 





Source link