New 'Storm' Infostealer Remotely Decrypts Stolen Credentials

2026-04-03T02:52:16Zcf31cae63caa50a16e3b70eb209800fd59428df0088032b5671b1fd6612edd3b
ai-related-vulnerabilitiesaitm-phishingakiracitrix-netscalerclickfix-techniquescredential-theftcrypto-theftf5-big-ipgithub-c2infostealermalware-as-a-servicenpm-compromisepypi-compromiseransomwarerapid-weaponizationserver-side-decryptionsupply-chain-compromiseteampcpvulnerabilitieszero-day-exploitation

What happened

Broad surge in active, fast-moving cyber threats: modern infostealers (Storm, Venom, Phantom) and MaaS platforms automate credential/crypto theft and bypass defenses (server-side decryption, ClickFix techniques). Multiple high-risk supply‑chain compromises (npm axios, PyPI packages, GitHub covert-channel C2) and rapid weaponization of critical RCEs (Oracle WebLogic) are being observed alongside in‑the‑wild exploitation of Citrix NetScaler and urgent patching guidance for F5 BIG‑IP. Ransomware operations have accelerated (Akira completes full attacks sub‑hour), AI-related risks are rising (vuln

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
cf31cae63caa50a16e3b70eb209800fd59428df0088032b5671b1fd6612edd3b
Enrichment time
2026-04-03T02:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.