threat-intel
'Djinn' Stealer Targets Cloud, AI Credentials
High
Summary
The ‘Djinn’ stealer, delivered via a SimpleHelp vulnerability (CVE-2026-48558), is targeting cloud and AI credentials, specifically focusing on developer and administrator environments. Blackpoint Cyber’s APG tracked an attack leveraging this vulnerability to deploy the TaskWeaver malware, which then utilized Djinn Stealer to steal sensitive data including SSH keys, API keys, and credentials for AI development tools like Claude and Gemini. This highlights a growing trend of attackers targeting trusted administrative systems to amplify the impact of initial compromises.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
