New 'Storm' Infostealer Remotely Decrypts Stolen Credentials
2026-04-02T20:52:17Z•0f8fa5ba022926752bb0ce882e49def0f48bbc94a5bc2c29835e2a2c33a2db23
AiTM phishing (TikTok for Business)`,`iOS DarkSword patching`,`NAkiraCVE-2025-53521CVE-2026-3055Citrix NetScalerF5 BIG-IPGitHub C2LNK filesMaaSOracle WebLogicPay2KeyPhantom StealerPyPI compromiseRATStorm infostealerVenom Stealercredential theftinfostealernpm compromisephishingransomwarerapid weaponizationserver-side decryptionsupply-chain compromisezero-day exploitation
What happened
A broad surge in opportunistic and sophisticated cyber activity: multiple new and evolved infostealers (notably ‘Storm’ using server‑side decryption to evade controls, Venom and Phantom MaaS offerings) and covert malware delivery channels (npm/axios and PyPI compromises, GitHub used as C2 via LNK files). Critical and rapidly weaponized vulnerabilities are being actively exploited in the wild (Citrix NetScaler CVE‑2026‑3055; urgent patching urged for F5 BIG‑IP CVE‑2025‑53521), while ransomware groups (Akira, Pay2Key) reduce dwell time to under an hour. Other trends include AiTM phishing (target
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 0f8fa5ba022926752bb0ce882e49def0f48bbc94a5bc2c29835e2a2c33a2db23
- Enrichment time
- 2026-04-02T20:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.