New 'Storm' Infostealer Remotely Decrypts Stolen Credentials
2026-04-03T02:52:16Z•cf31cae63caa50a16e3b70eb209800fd59428df0088032b5671b1fd6612edd3b
ai-related-vulnerabilitiesaitm-phishingakiracitrix-netscalerclickfix-techniquescredential-theftcrypto-theftf5-big-ipgithub-c2infostealermalware-as-a-servicenpm-compromisepypi-compromiseransomwarerapid-weaponizationserver-side-decryptionsupply-chain-compromiseteampcpvulnerabilitieszero-day-exploitation
What happened
Broad surge in active, fast-moving cyber threats: modern infostealers (Storm, Venom, Phantom) and MaaS platforms automate credential/crypto theft and bypass defenses (server-side decryption, ClickFix techniques). Multiple high-risk supply‑chain compromises (npm axios, PyPI packages, GitHub covert-channel C2) and rapid weaponization of critical RCEs (Oracle WebLogic) are being observed alongside in‑the‑wild exploitation of Citrix NetScaler and urgent patching guidance for F5 BIG‑IP. Ransomware operations have accelerated (Akira completes full attacks sub‑hour), AI-related risks are rising (vuln
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- cf31cae63caa50a16e3b70eb209800fd59428df0088032b5671b1fd6612edd3b
- Enrichment time
- 2026-04-03T02:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.