{"id":24428,"date":"2026-05-28T10:26:09","date_gmt":"2026-05-28T03:26:09","guid":{"rendered":"https:\/\/fpt-is.com\/en\/?post_type=goc_nhin_so&#038;p=24428"},"modified":"2026-07-14T09:57:47","modified_gmt":"2026-07-14T02:57:47","slug":"the-underground-access-economy-storm-infostealer-and-the-era-of-passwordless-attacks","status":"publish","type":"goc_nhin_so","link":"https:\/\/fpt-is.com\/en\/insights\/the-underground-access-economy-storm-infostealer-and-the-era-of-passwordless-attacks\/","title":{"rendered":"The underground access economy: Storm Infostealer and the era of passwordless attacks"},"content":{"rendered":"<h2 id=\"executive-summary\"><span style=\"font-family: arial, helvetica, sans-serif\">Executive Summary<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">In early 2026, Varonis Threat Labs identified\u00a0<strong>Storm<\/strong> &#8211; a new infostealer circulating on underground cybercrime networks for under $1,000 per month. Storm is not simply another commodity stealer: it represents the next evolutionary step in how attackers compromise digital identities <strong>without ever needing a password or triggering MFA<\/strong>.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Varonis&#8217; panel analysis confirmed\u00a0<strong>1,715 victims<\/strong>\u00a0across multiple countries, including\u00a0<strong>Vietnam<\/strong>. A single Storm-infected browser can hand an operator authenticated access to an organization&#8217;s entire SaaS estate, cloud environment, and internal tools &#8211; through valid, already-authenticated session cookies, without triggering any password-based detection.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Storm does not exist in a vacuum. It is a product of a\u00a0<strong>mature access economy<\/strong> &#8211; an underground ecosystem where every link in the attack chain has been specialized, priced, and commoditized.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Highest priority action:<\/strong>\u00a0Immediately review browser-based credential storage policy for privileged accounts, and enable alerting for impossible travel and fresh token anomalies in Entra ID \/ Google Workspace.<\/span><\/p>\n<h2 id=\"1-the-access-economy-when-attacks-become-an-industry\"><span style=\"font-family: arial, helvetica, sans-serif\">1. The Access Economy: When attacks become an industry<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">&#8220;Attackers don&#8217;t break in, they log in&#8221; is no longer just a warning &#8211; it is an accurate description of a functioning business model.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Underground marketplaces now operate with the full infrastructure of a legitimate market: reputation systems for sellers, escrow to guarantee transactions, role specialization, and tiered pricing by target value. One operator runs infostealers across thousands of machines. Another extracts and sorts credentials. A third sells curated access. A fourth deploys ransomware. Each party focuses on their specialty, and the entire chain operates with disturbing efficiency.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Four primary product categories are traded in this market:<\/span><\/p>\n<h3 id=\"11-remote-access-credentials\"><span style=\"font-family: arial, helvetica, sans-serif\">1.1 Remote access credentials<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">VPN and RDP credentials are listed with full metadata: organization name, geographic region, industry, and VPN product in use. Pricing scales with target value. Varonis documented a confirmed seller offering\u00a0<strong>seven Fortinet SSL VPN credentials<\/strong> targeting educational institutions &#8211; a lower-value market. Credentials for financial organizations or government agencies command significantly higher prices, sometimes with &#8220;exclusive access&#8221; guarantees &#8211; meaning the seller will not sell the same access to multiple buyers simultaneously.<\/span><\/p>\n<h3 id=\"12-infostealer-logs\"><span style=\"font-family: arial, helvetica, sans-serif\">1.2 Infostealer logs<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">This is the largest product category by volume. Infostealer families including Redline, Raccoon, Vidar, Lumma, and Risepro harvest browser-saved passwords, session cookies, autofill data, cryptocurrency wallet seeds, and authentication tokens &#8211; then distribute structured, searchable logs through subscription channels.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\"><strong>DAISY CLOUD<\/strong>\u00a0is a representative example: a stealer log distribution service operating on subscription at $400 for seven days or $1,350 per month. Logs are indexed and searchable by credential type, country, and platform.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Session cookies are the highest-value product in this category. If an infostealer captures a valid cookie, an attacker can import it directly into a browser and inherit the fully authenticated session &#8211; <strong>no password needed, no MFA prompt triggered<\/strong>.<\/span><\/p>\n<h3 id=\"13-breach-databases\"><span style=\"font-family: arial, helvetica, sans-serif\">1.3 Breach databases<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Data from historical breaches is categorized by geography, sector, freshness, and field completeness (does the record include email + phone + password hash?). This data serves multiple purposes: credential stuffing, organizational reconnaissance, and building employee profiles for targeted spear-phishing.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">One example documented in Varonis research: a dump from three Egyptian government ministries containing 24,000 HTML files and thousands of PDFs with citizen records.<\/span><\/p>\n<h3 id=\"14-web-shells-and-backdoors\"><span style=\"font-family: arial, helvetica, sans-serif\">1.4 Web shells and backdoors<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Web shells bypass authentication entirely. These are backdoors planted on already-compromised servers that give buyers command execution capability over HTTP without any credentials. Once installed, a web shell persists independently of the original vulnerability &#8211; patching the vulnerability does not remove the shell.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">One listing Varonis documented: root RCE and shell access to a\u00a0<strong>government revenue management system<\/strong> (Linux, root-level permissions) &#8211; priced at $400, from a seller with a reputation score of 61 built over four months of operation.<\/span><\/p>\n<h2 id=\"2-storm-a-next-generation-infostealer\"><span style=\"font-family: arial, helvetica, sans-serif\">2. Storm &#8211; A next-generation Infostealer<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Storm is the clearest evidence of where infostealers are heading: from raw data dumping tools to\u00a0<strong>automated identity takeover platforms<\/strong>.<\/span><\/p>\n<h3 id=\"21-technical-context-why-server-side-decryption-matters\"><span style=\"font-family: arial, helvetica, sans-serif\">2.1 Technical context: Why server-side decryption matters<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Traditional infostealers decrypted browser credentials on the victim&#8217;s machine by loading SQLite libraries and directly accessing credential stores. EDR and endpoint security tools adapted to this &#8211; anomalous access to browser databases became one of the clearest signals of malicious activity on an endpoint.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">In July 2024, Google deployed\u00a0<strong>App-Bound Encryption<\/strong>\u00a0in Chrome 127, binding encryption keys to the Chrome process itself and making local decryption significantly harder. This is where Storm and next-generation stealers pivoted: rather than decrypting on the endpoint, they\u00a0<strong>exfiltrate the encrypted data blob to the attacker&#8217;s server and decrypt it there<\/strong>.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">The result: no suspicious SQLite access on the endpoint, no browser credential store access anomaly &#8211; the signals that EDR was trained to detect are simply absent.<\/span><\/p>\n<h3 id=\"22-data-collected\"><span style=\"font-family: arial, helvetica, sans-serif\">2.2 Data collected<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Storm harvests everything an operator needs to restore a hijacked session remotely:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Saved passwords and autofill data<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Session cookies (all browsers)<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Google account tokens and refresh tokens<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Browser-saved credit card data<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Browsing history<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Session data from\u00a0<strong>Telegram, Signal, and Discord<\/strong><\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Cryptocurrency wallets via both browser extensions and desktop apps<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Documents from user directories<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">System information and screenshots Storm handles both\u00a0<strong>Chromium-based browsers<\/strong>\u00a0(Chrome, Edge, Brave) and\u00a0<strong>Gecko-based browsers<\/strong> (Firefox, Waterfox, Pale Moon) &#8211; entirely server-side. This distinguishes it from StealC V2, which still processes Firefox locally.<\/span><\/li>\n<\/ul>\n<h3 id=\"23-the-session-restore-feature-the-most-dangerous-capability\"><span style=\"font-family: arial, helvetica, sans-serif\">2.3 The Session restore feature: The most dangerous capability<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">After decrypting the stolen data, Storm does not simply dump credentials into an operator panel for manual exploitation. It\u00a0<strong>automates the next step<\/strong>:<\/span><\/p>\n<ol>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">The operator supplies the victim&#8217;s Google Refresh Token into the panel<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Combined with a SOCKS5 proxy geographically matched to the victim (same country\/ISP)<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">The panel silently restores the victim&#8217;s authenticated session The result: the operator has a live, authenticated session originating from a geographically plausible IP address, triggering no password-based alerts. Every SaaS platform the victim was logged into &#8211; Microsoft 365, Google Workspace, Salesforce, internal tools \u2014 is now accessible to the attacker.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">This technique is not new: Varonis&#8217;\u00a0<strong>Cookie-Bite<\/strong>\u00a0research demonstrated that stolen Azure Entra ID session cookies completely neutralize MFA.\u00a0<strong>SessionShark<\/strong>\u00a0showed phishing kits intercepting session tokens in real time. Storm is the\u00a0<strong>productization<\/strong> of these known techniques &#8211; packaged into a subscription service with operator-friendly UX.<\/span><\/p>\n<h3 id=\"24-confirmed-scope\"><span style=\"font-family: arial, helvetica, sans-serif\">2.4 Confirmed scope<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Varonis found\u00a0<strong>1,715 entries<\/strong>\u00a0in panel data, originating from Brazil, Ecuador, India, Indonesia,\u00a0<strong>Vietnam<\/strong>, and the United States. While not all entries can be confirmed as genuine victims (test data may be included), the diversity of IP addresses, ISPs, and data sizes indicates\u00a0<strong>active malicious campaigns<\/strong>\u00a0are ongoing.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Stolen credentials cover a range of high-value platforms including Google, Facebook, Twitter\/X, financial accounts, and corporate SaaS.<\/span><\/p>\n<h2 id=\"3-kill-chain\"><span style=\"font-family: arial, helvetica, sans-serif\">3. Kill chain<\/span><\/h2>\n<pre><span style=\"font-family: arial, helvetica, sans-serif\"><code class=\"hljs language-pgsql\" data-highlighted=\"yes\">[Infection Vector]\r\nPhishing email \/ Malicious download \/ Compromised third-party tool\r\n         \u2502\r\n         \u25bc\r\n[Collection \u2014 Endpoint]\r\nStorm harvests: passwords, cookies, tokens, wallets, documents\r\n\u2192 <span class=\"hljs-keyword\">No<\/span> <span class=\"hljs-keyword\">local<\/span> decryption, <span class=\"hljs-keyword\">no<\/span> direct SQLite <span class=\"hljs-keyword\">access<\/span>\r\n\u2192 Packages data <span class=\"hljs-keyword\">as<\/span> <span class=\"hljs-keyword\">encrypted<\/span> blob\r\n         \u2502\r\n         \u25bc\r\n[Exfiltration \u2192 C2 <span class=\"hljs-keyword\">Server<\/span>]\r\n<span class=\"hljs-keyword\">Encrypted<\/span> blob shipped <span class=\"hljs-keyword\">to<\/span> attacker-controlled <span class=\"hljs-keyword\">server<\/span>\r\n         \u2502\r\n         \u25bc\r\n[<span class=\"hljs-keyword\">Server<\/span>-Side Decryption]\r\nAttacker <span class=\"hljs-keyword\">server<\/span> decrypts <span class=\"hljs-keyword\">all<\/span> browser data\r\n\u2192 Credentials <span class=\"hljs-keyword\">and<\/span> <span class=\"hljs-keyword\">session<\/span> cookies dumped <span class=\"hljs-keyword\">to<\/span> <span class=\"hljs-keyword\">operator<\/span> panel\r\n         \u2502\r\n         \u25bc\r\n[<span class=\"hljs-keyword\">Session<\/span> Restore \u2014 Automation]\r\nGoogle <span class=\"hljs-keyword\">Refresh<\/span> Token + SOCKS5 proxy (geo-matched <span class=\"hljs-keyword\">to<\/span> victim)\r\n\u2192 Panel silently restores authenticated <span class=\"hljs-keyword\">session<\/span>\r\n         \u2502\r\n         \u25bc\r\n[Impact]\r\nAuthenticated <span class=\"hljs-keyword\">access<\/span> <span class=\"hljs-keyword\">to<\/span> SaaS, cloud, <span class=\"hljs-type\">internal<\/span> tools\r\n\u2192 <span class=\"hljs-keyword\">No<\/span> <span class=\"hljs-keyword\">password<\/span> alert triggered, <span class=\"hljs-keyword\">no<\/span> MFA required\r\n<\/code><button class=\"copy-code-button\" title=\"Copy code\" aria-label=\"Copy code\"><i class=\"fa-jelly fa-clipboard copy-icon\"><\/i><\/button><\/span><\/pre>\n<h2 id=\"4-mitre-attampck-mapping\"><span style=\"font-family: arial, helvetica, sans-serif\">4. MITRE ATT&amp;CK Mapping<\/span><\/h2>\n<table>\n<thead>\n<tr>\n<th><span style=\"font-family: arial, helvetica, sans-serif\">Tactic<\/span><\/th>\n<th><span style=\"font-family: arial, helvetica, sans-serif\">Technique ID<\/span><\/th>\n<th><span style=\"font-family: arial, helvetica, sans-serif\">Technique Name<\/span><\/th>\n<th><span style=\"font-family: arial, helvetica, sans-serif\">Notes<\/span><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Initial Access<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1566<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Phishing<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Primary delivery vector<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Initial Access<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1078<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Valid Accounts<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Using purchased VPN\/RDP credentials from market<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Credential Access<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1555.003<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Credentials from Web Browsers<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Core Storm capability<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Credential Access<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1539<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Steal Web Session Cookie<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Priority target<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Credential Access<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1528<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Steal Application Access Token<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Google Refresh Token<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Defense Evasion<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1027<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Obfuscated Files or Information<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Encrypted blob avoids local detection<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Exfiltration<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1041<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Exfiltration Over C2 Channel<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Encrypted blob shipped to attacker server<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Persistence<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1505.003<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Web Shell<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Applies to web shell access brokers<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Initial Access<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1190<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Exploit Public-Facing Application<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Vector for web shell installation<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Lateral Movement<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">T1550.004<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Web Session Cookie<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Using cookie to pivot across services<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"5-detection-amp-threat-hunting\"><span style=\"font-family: arial, helvetica, sans-serif\">5. Detection &amp; Threat hunting<\/span><\/h2>\n<h3 id=\"51-endpoint-signals-microsoft-defender-for-endpoint\"><span style=\"font-family: arial, helvetica, sans-serif\">5.1 Endpoint signals (Microsoft Defender for Endpoint)<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">With server-side decryption, local signals are weaker than previous-generation stealers &#8211; but they do not disappear entirely:<\/span><\/p>\n<pre><span style=\"font-family: arial, helvetica, sans-serif\"><code class=\"language-kql\">\/\/ Detect anomalous child processes spawned by browsers \u2014 potential Storm loader activity\r\nDeviceProcessEvents\r\n| where InitiatingProcessFileName in~ (\"chrome.exe\", \"msedge.exe\", \"firefox.exe\")\r\n| where FileName !in~ (\"chrome.exe\", \"msedge.exe\", \"firefox.exe\", \"crashpad_handler.exe\")\r\n| where ProcessCommandLine !contains \"extension\"\r\n| project Timestamp, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine\r\n| order by Timestamp desc\r\n<\/code><button class=\"copy-code-button\" title=\"Copy code\" aria-label=\"Copy code\"><i class=\"fa-jelly fa-clipboard copy-icon\"><\/i><\/button><\/span><\/pre>\n<pre><span style=\"font-family: arial, helvetica, sans-serif\"><code class=\"language-kql\">\/\/ Monitor anomalous access to browser credential stores\r\nDeviceFileEvents\r\n| where FolderPath has_any (\r\n    @\"\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data\",\r\n    @\"\\AppData\\Local\\Microsoft\\Edge\\User Data\\Default\\Login Data\",\r\n    @\"\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\"\r\n)\r\n| where InitiatingProcessFileName !in~ (\"chrome.exe\", \"msedge.exe\", \"firefox.exe\", \"MicrosoftEdgeUpdate.exe\")\r\n| project Timestamp, DeviceName, InitiatingProcessFileName, FolderPath, ActionType\r\n<\/code><button class=\"copy-code-button\" title=\"Copy code\" aria-label=\"Copy code\"><i class=\"fa-jelly fa-clipboard copy-icon\"><\/i><\/button><\/span><\/pre>\n<h3 id=\"52-identity-signals-microsoft-entra-id\"><span style=\"font-family: arial, helvetica, sans-serif\">5.2 Identity signals (Microsoft entra ID)<\/span><\/h3>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Session hijacking leaves clear traces at the identity layer &#8211; this is where detection is most effective:<\/span><\/p>\n<pre><span style=\"font-family: arial, helvetica, sans-serif\"><code class=\"language-kql\">\/\/ Impossible travel following successful sign-in \u2014 indicates session restore with proxy\r\nSigninLogs\r\n| where ResultType == 0\r\n| summarize \r\n    Locations = make_set(Location),\r\n    IPAddresses = make_set(IPAddress),\r\n    Count = count()\r\n    by UserPrincipalName, bin(TimeGenerated, 1h)\r\n| where array_length(Locations) &gt; 1\r\n| project TimeGenerated, UserPrincipalName, Locations, IPAddresses, Count\r\n<\/code><button class=\"copy-code-button\" title=\"Copy code\" aria-label=\"Copy code\"><i class=\"fa-jelly fa-clipboard copy-icon\"><\/i><\/button><\/span><\/pre>\n<pre><span style=\"font-family: arial, helvetica, sans-serif\"><code class=\"language-kql\">\/\/ Refresh token use from unknown IP \u2014 Google Refresh Token abuse pattern\r\nAADNonInteractiveUserSignInLogs\r\n| where AuthenticationProtocol == \"refreshToken\"\r\n| where NetworkLocationDetails !contains \"trustedNamedLocation\"\r\n| join kind=leftouter (\r\n    SigninLogs\r\n    | where TimeGenerated &gt; ago(30d)\r\n    | summarize KnownIPs = make_set(IPAddress) by UserPrincipalName\r\n) on UserPrincipalName\r\n| where IPAddress !in (KnownIPs)\r\n| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName, Location\r\n<\/code><button class=\"copy-code-button\" title=\"Copy code\" aria-label=\"Copy code\"><i class=\"fa-jelly fa-clipboard copy-icon\"><\/i><\/button><\/span><\/pre>\n<h3 id=\"53-network-signals\"><span style=\"font-family: arial, helvetica, sans-serif\">5.3 Network signals<\/span><\/h3>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Monitor outbound connections from endpoints to non-whitelisted IPs\/domains, particularly following user login activity<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">SOCKS5 proxy traffic combined with anomalous browser activity &#8211; consistent with session restore operations<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Large encrypted outbound transfers from workstations (encrypted blob exfiltration)<\/span><\/li>\n<\/ul>\n<h3 id=\"54-required-log-sources\"><span style=\"font-family: arial, helvetica, sans-serif\">5.4 Required log sources<\/span><\/h3>\n<table>\n<thead>\n<tr>\n<th><span style=\"font-family: arial, helvetica, sans-serif\">Source<\/span><\/th>\n<th><span style=\"font-family: arial, helvetica, sans-serif\">Purpose<\/span><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">MDE \u2014 Process Creation<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Detect Storm loader \/ child process anomaly<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">MDE \u2014 File Events<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Monitor browser credential store access<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Entra ID Sign-in Logs<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Session hijack detection, impossible travel<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Entra ID Non-Interactive Logs<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Refresh token abuse detection<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Network Proxy Logs<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Exfiltration and SOCKS5 detection<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Microsoft Sentinel \u2014 UEBA<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif\">Behavioral baseline for user sessions<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"6-ioc-amp-artifacts\"><span style=\"font-family: arial, helvetica, sans-serif\">6. IOC &amp; Artifacts<\/span><\/h2>\n<pre><span style=\"font-family: arial, helvetica, sans-serif\"><code class=\"hljs language-nix\" data-highlighted=\"yes\"><span class=\"hljs-comment\"># Related Infostealer Ecosystem<\/span>\r\nRedline Stealer\r\nRaccoon Stealer\r\nVidar\r\nLumma Stealer\r\nRisepro\r\n \r\n<span class=\"hljs-comment\"># Distribution Services<\/span>\r\nDAISY CLOUD (stealer log subscription service)\r\n  \u2192 <span class=\"hljs-params\">Pricing:<\/span> \\(<span class=\"hljs-number\">400<\/span> <span class=\"hljs-symbol\">\/<\/span> <span class=\"hljs-number\">7<\/span> days | \\)<span class=\"hljs-number\">1<\/span>,<span class=\"hljs-number\">350<\/span> <span class=\"hljs-symbol\">\/<\/span> month\r\n \r\n<span class=\"hljs-comment\"># Storm Binary Hashes<\/span>\r\n[NEEDS <span class=\"hljs-params\">VERIFICATION:<\/span> Varonis has not released specific Storm binary hashes <span class=\"hljs-keyword\">in<\/span> open sources]\r\n \r\n<span class=\"hljs-comment\"># Storm C2 Infrastructure<\/span>\r\n[NEEDS <span class=\"hljs-params\">VERIFICATION:<\/span> C2 domains<span class=\"hljs-symbol\">\/IPs<\/span> not published <span class=\"hljs-keyword\">in<\/span> public reporting at time of writing]\r\n \r\n<span class=\"hljs-comment\"># Session Restore Technique Indicator<\/span>\r\nGoogle Refresh Token abuse <span class=\"hljs-operator\">+<\/span> geographically matched SOCKS5 proxy\r\n\u2192 Detect <span class=\"hljs-params\">via:<\/span> AADNonInteractiveUserSignInLogs <span class=\"hljs-keyword\">with<\/span> refreshToken auth from unknown IP\r\n<\/code><button class=\"copy-code-button\" title=\"Copy code\" aria-label=\"Copy code\"><i class=\"fa-jelly fa-clipboard copy-icon\"><\/i><\/button><\/span><\/pre>\n<h2 id=\"7-analysis\"><span style=\"font-family: arial, helvetica, sans-serif\">7. Analysis<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">Storm is not a zero-day and does not rely on fundamentally new techniques. Every core capability &#8211; server-side decryption, session cookie theft, refresh token abuse &#8211; has been previously documented. What Storm does is <strong>productize<\/strong>\u00a0the entire workflow into a subscription service with an operator interface simple enough that technical depth is no longer required.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">This is more concerning than any novel technique:\u00a0<strong>the barrier to entry for identity-based attacks continues to fall<\/strong>.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">The presence of Vietnam in Storm&#8217;s panel data is a specific signal, not a general warning. Multiple financial institutions and government agencies in Vietnam currently use browser-based SSO and OAuth for internal systems &#8211; this is a direct attack surface. An employee with an active browser session into a core banking web portal, or into a Microsoft 365 tenant, is a high-value target for a Storm operator.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">The broader trend is clear: infostealers are rapidly shifting from\u00a0<strong>noisy local theft<\/strong>\u00a0(increasingly caught by EDR) toward\u00a0<strong>server-side stealth<\/strong>\u00a0with higher automation. In the next two years, session hijacking will become the primary initial access vector for account takeover, displacing traditional credential stuffing that MFA has largely throttled.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\">A critical operational point for SOC teams:\u00a0<strong>an infostealer incident is an identity incident<\/strong>. Remediating the malware on the endpoint and closing the ticket is insufficient. The full response must include reviewing all SaaS OAuth grants, mailbox rules, and SSO integrations &#8211; immediately after confirming infection. Any session active at the time of compromise should be considered stolen until proven otherwise.<\/span><\/p>\n<h2 id=\"8-recommendations\"><span style=\"font-family: arial, helvetica, sans-serif\">8. Recommendations<\/span><\/h2>\n<h3 id=\"immediate-0-24h\"><span style=\"font-family: arial, helvetica, sans-serif\">Immediate (0-24h)<\/span><\/h3>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Audit browser credential storage policy:<\/strong>\u00a0Stop saving passwords for high-value accounts (admin portals, banking systems, cloud consoles) in browsers. Enforce a dedicated password manager with administrative controls.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Enable Entra ID UEBA alerting:<\/strong>\u00a0Configure alerts for impossible travel, refresh token use from unknown locations, and sign-ins originating from anonymous proxies or SOCKS endpoints.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Revoke active sessions:<\/strong>\u00a0For admin and privileged accounts, revoke all active session tokens and require re-authentication.<\/span><\/li>\n<\/ul>\n<h3 id=\"short-term-1-7-days\"><span style=\"font-family: arial, helvetica, sans-serif\">Short-term (1-7 days)<\/span><\/h3>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Deploy phishing-resistant MFA:<\/strong>\u00a0FIDO2\/passkeys for high-privilege accounts. Note: TOTP and SMS-based MFA do not protect against session hijacking post-authentication.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Threat hunt:<\/strong>\u00a0Search for anomalous browser child processes and file access to browser credential stores initiated by non-browser processes.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Audit OAuth grants and SSO:<\/strong>\u00a0Revoke grants for third-party applications no longer in use. Identify OAuth applications recently authorized outside of normal approval workflows.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Monitor SOCKS5 traffic:<\/strong>\u00a0Outbound SOCKS5 from workstations not on an established whitelist is a high-confidence indicator.<\/span><\/li>\n<\/ul>\n<h3 id=\"long-term\"><span style=\"font-family: arial, helvetica, sans-serif\">Long-term<\/span><\/h3>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Build an &#8220;Infostealer = Identity Incident&#8221; playbook:<\/strong>\u00a0Steps must include session revocation, OAuth grant audit, mailbox rule review, SSO integration check, and HR notification regarding potential data exposure scope.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Session lifetime enforcement:<\/strong>\u00a0Enforce short-lived session tokens across SaaS platforms. Negotiate configurable session timeout with vendors where this is not default.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Continuous authentication evaluation:<\/strong>\u00a0Assess solutions that enforce re-authentication when location shift or device fingerprint change is detected within an active session.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\"><strong>Underground monitoring:<\/strong>\u00a0Subscribe to threat intelligence feeds covering stealer log marketplaces to detect early when organizational credentials appear in underground channels.<\/span><\/li>\n<\/ul>\n<h2 id=\"9-references\"><span style=\"font-family: arial, helvetica, sans-serif\">9. References<\/span><\/h2>\n<ol>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Varonis Threat Labs, Daniel Kelley &#8211; <em>A Quiet &#8220;Storm&#8221;: Infostealer Hijacks Sessions, Decrypts Server-Side<\/em>\u00a0(April 2026):\u00a0<a href=\"https:\/\/www.varonis.com\/blog\/storm-infostealer\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/www.varonis.com\/blog\/storm-infostealer<\/a><\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Varonis Threat Labs, Daniel Kelley &#8211; <em>How Cybercriminals Buy Access: Logins, Cookies, and Backdoors<\/em>\u00a0(February 2026):\u00a0<a href=\"https:\/\/www.varonis.com\/blog\/how-hackers-buy-access\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/www.varonis.com\/blog\/how-hackers-buy-access<\/a><\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Varonis Threat Labs &#8211; <em>Cookie-Bite: Stolen Azure Entra ID Session Cookies and MFA Bypass<\/em>:\u00a0<a href=\"https:\/\/www.varonis.com\/blog\/cookie-bite\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/www.varonis.com\/blog\/cookie-bite<\/a><\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">BleepingComputer &#8211; <em>The silent &#8220;Storm&#8221;: New infostealer hijacks sessions, decrypts server-side<\/em>\u00a0(April 2026):\u00a0<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/the-silent-storm-new-infostealer-hijacks-sessions-decrypts-server-side\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/www.bleepingcomputer.com\/news\/security\/the-silent-storm-new-infostealer-hijacks-sessions-decrypts-server-side\/<\/a><\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">Infosecurity Magazine &#8211; <em>New &#8216;Storm&#8217; Infostealer Remotely Decrypts Stolen Credentials<\/em>\u00a0(April 2026):\u00a0<a href=\"https:\/\/www.infosecurity-magazine.com\/news\/storm-infostealer-remotely\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/www.infosecurity-magazine.com\/news\/storm-infostealer-remotely\/<\/a><\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">MITRE ATT&amp;CK &#8211; T1539: Steal Web Session Cookie: <a href=\"https:\/\/attack.mitre.org\/techniques\/T1539\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/attack.mitre.org\/techniques\/T1539\/<\/a><\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif\">MITRE ATT&amp;CK &#8211; T1555.003: Credentials from Web Browsers: <a href=\"https:\/\/attack.mitre.org\/techniques\/T1555\/003\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/attack.mitre.org\/techniques\/T1555\/003\/<\/a><\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<table style=\"border-collapse: collapse;width: 100%\">\n<tbody>\n<tr>\n<td style=\"width: 100%\"><em><span style=\"font-family: arial, helvetica, sans-serif\"><strong data-start=\"0\" data-end=\"41\" data-is-only-node=\"\">Exclusive article by an FPT IS expert<\/strong><\/span><\/em><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif\"><strong data-start=\"44\" data-end=\"93\" data-is-last-node=\"\">Vu Nhat Lam \u2013 FPT Information Security Center, FPT Corp<\/strong><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"author":21,"featured_media":0,"parent":0,"template":"","nang_luc":[821],"danh_muc_goc_nhin_so":[],"dich_vu":[],"linh_vuc":[],"platform":[],"san_pham":[],"the_goc_nhin_so":[],"class_list":["post-24428","goc_nhin_so","type-goc_nhin_so","status-publish","hentry","nang_luc-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/goc_nhin_so\/24428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/goc_nhin_so"}],"about":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/types\/goc_nhin_so"}],"author":[{"embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/users\/21"}],"wp:attachment":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/media?parent=24428"}],"wp:term":[{"taxonomy":"nang_luc","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/nang_luc?post=24428"},{"taxonomy":"danh_muc_goc_nhin_so","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/danh_muc_goc_nhin_so?post=24428"},{"taxonomy":"dich_vu","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/dich_vu?post=24428"},{"taxonomy":"linh_vuc","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/linh_vuc?post=24428"},{"taxonomy":"platform","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/platform?post=24428"},{"taxonomy":"san_pham","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/san_pham?post=24428"},{"taxonomy":"the_goc_nhin_so","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/the_goc_nhin_so?post=24428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}