Key Features of StormKitty Stealer 2025
1. Credential Theft
1. Credential Theft- Extracts saved passwords from browsers (Chrome, Firefox, Edge, Brave).
- Steals FTP, VPN, and email client credentials (Outlook, Thunderbird).
- Log Windows login credentials via memory scraping.
- Targets MetaMask, Exodus, Trust Wallet, and Binance Chain Wallet.
- Steals private keys, seed phrases, and wallet.dat files.
- Monitors the clipboard for crypto addresses (swaps the victim’s address with the attacker’s).
- Steals cookies & session tokens (allowing account takeovers).
- Bypasses two-factor authentication (2FA) by hijacking active sessions.
- Target social media, banking, and cloud storage logins.
- Gathers IP address, geolocation, installed software, and hardware specs.
- Extracts Wi-Fi passwords for lateral network movement.
- Checks for virtual machines (VMs) & sandboxes to evade analysis.
- Code obfuscation
- Delayed execution
- Process hollowing
- Disables Windows Defender & other AVs
- Ransomware module
- Keylogger
- Discord token grabber