Skip to main content

Tag: credential harvesting

87 articles

Rack of networking equipment including a Cisco router in a control room.

Fire Ant Exploits Cisco Routers to Harvest Credentials and Evade Detection

When hackers take control of routers like Cisco's IOS XR, they don't just gain access - they gain a bird's-eye view of the entire network, allowing them to harvest sensitive credentials and fly under the radar. The notorious Fire Ant group recently exploited these routers to turn them into intelligence collection platforms, putting countless networks at risk.

Analyst 207
Cluttered software development workspace with laptop, coding materials, and RubyGems packages in a bright, neutral-colored…

Typosquatting Campaign Targets RubyGems Users with Windows Stealer

Beware of a sneaky typosquatting campaign targeting RubyGems users: 16 malicious packages were used to spread a Windows stealer that harvests sensitive data, including browser credentials, cryptocurrency wallets, and Telegram info. This malware can strike when you least expect it, putting your online security at risk.

Analyst 207
Public Wi-Fi access point in a hotel lobby with a blurred laptop screen nearby.

Hackers Exploit Public Wi-Fi DNS to Harvest Credentials

Beware of hackers lurking on public Wi-Fi networks at hotels, conference centers, and other hotspots, who are using a sneaky trick to steal your login credentials by hijacking the network's DNS settings. By changing just one setting, they can redirect you to fake login pages that look legit - and that's all they need to get their hands on your sensitive info.

Analyst 207
Laptop on a desk in a neutral office setting with blurred screen.

CTM360 Exposes Global Recruitment Phishing Campaign Using Browser-in-the-Browser Traps

Beware of a sneaky recruitment phishing scam that used fake interview pages and a clever Browser-in-the-Browser trick to steal Google and Facebook credentials from over 3,000 unsuspecting victims in just two months. This cunning attack even fooled multi-factor authentication, putting countless users at risk.

Analyst 207
Server room interior with technicians and rows of computer equipment.

Infostealers Harvest 1.7 Billion Credentials in Six Months

Cybercriminals have supercharged their credential-harvesting capabilities, with infostealer malware infecting 7.4 million devices and snagging a staggering 1.7 billion credentials in just six short months. This automated threat landscape redefines the speed and scale of a breach.

Analyst 207
Network equipment and routers in a server room with a prominent router in the foreground.

Evooo1Bot Malware Targets Routers in Global Traffic Relay Botnet

Meet Evooo1Bot, a sneaky malware that's turning routers worldwide into unwitting traffic relays, harvesting credentials, and launching devastating DDoS attacks. This modular Linux botnet is packed with powerful tools, including encrypted communication, SSH brute-forcing, and exploit arsenals to take down vulnerable devices.

Analyst 207
Blurred laptop screen on cluttered office desk with hand hovering over keyboard.

AI Compresses Identity Attacks, Forces Device Trust Reassessment

Identity security is buckling under the strain of increasingly sophisticated threats, with stolen credentials remaining a top vulnerability - a whopping 44.7% of breaches involve compromised login details. AI is now compressing the time and effort attackers need to launch identity attacks, forcing a urgent reevaluation of device trust.

Analyst 207
Modern office setting with laptop, phone, and paper with scribbles on a desk.

Greatness PhaaS Expands to Device Code Phishing

Meet Greatness, a phishing-as-a-service powerhouse that's upgraded its game, now offering a one-stop-shop for cybercriminals to mastermind credential theft, device code phishing, and OAuth consent abuse - all from a single, user-friendly dashboard. This commercial crimeware toolkit has evolved into a full-fledged ecosystem, supporting multiple platforms like iCloud, Yahoo, and Google Workspace.

Analyst 207
Cluttered software development workspace with laptop, papers, and cables.

Npm Worm Exploits Hundreds of Packages via Keyv Link

Hundreds of packages in the npm registry have been compromised by a worm exploiting a vulnerability in the Keyv library, with 353 poisoned versions across 79 package names verified. This malicious campaign uses a preinstall lifecycle command to spread and harvest sensitive credentials and secrets from various sources.

Analyst 207
Public Wi-Fi access point in a hotel equipment room.

Cybersecurity Experts Warn of Global Hotel Wi-Fi Credential Harvesting Campaign

Beware of hackers lurking on hotel Wi-Fi networks, as a global campaign is underway to steal sensitive credentials from unsuspecting travelers and businesses. Cyber attackers are exploiting weak spots in hotel routers and Wi-Fi systems to gain control and manipulate DNS settings.

Analyst 207
Law enforcement officers and investigators gather around a table with laptops and papers in a briefing room with a global…

Law Enforcement Disrupts Kratos Phishing Kit Targeting Microsoft 365 Sessions

In a major win for cybersecurity, law enforcement agencies have dismantled the notorious Kratos Phishing Kit, pulling over 200 servers offline and disrupting thousands of phishing campaigns targeting Microsoft 365 sessions. The operation, coordinated with Indonesian authorities, is estimated to have impacted around 1,800 paying customers who were using Kratos to run approximately 15,000 phishing campaigns monthly.

Analyst 207
Brightly-lit server stands out in dimly lit data center with blurred equipment and cityscape visible through a window.

Misconfigured Server Reveals Evilginx Phishing Operators

A shocking security blunder exposed the inner workings of a massive Evilginx phishing campaign, revealing 218 victims across 12 countries, with nearly 94% being corporate targets, who were quietly harvested over the course of a year. The careless mistake, made on a Budapest virtual private server, gave researchers a rare glimpse into the sophisticated phishing ecosystem.

Analyst 207
Cramped server room with laptop and cables in ordinary indoor lighting.

Evilginx Phishing Ops Expose Microsoft 365 MFA Weaknesses

A French security firm stumbled upon a live Microsoft 365 phishing operation when a simple Python command was left exposed in a readable file, revealing a treasure trove of sensitive data. This lucky discovery shed light on the alarming weaknesses in Microsoft 365's multi-factor authentication.

Analyst 207
Modern office building exterior in a business district at daytime.

ARToken Phishing Platform Exposes EvilTokens' Microsoft 365 Toolkit

Cisco Talos researchers have uncovered a sophisticated phishing platform, ARToken, that offers a Microsoft 365 toolkit and goes far beyond traditional credential-harvesting pages, exposing over 80 API endpoints. This phishing-as-a-service operation is a game-changer in the world of cyber threats.

Analyst 207
Network operations room with computer servers and equipment showing signs of affected infrastructure.

FortiBleed Exposes Link to Ransomware Ops

A shocking new report reveals that the notorious FortiBleed vulnerability has a direct link to ransomware operations, with a key player found negotiating with both groups. This alarming connection has led to at least 12 ransomware deployments and hundreds of encrypted endpoints.

Analyst 207
Developer workstation with laptop and subtle signs of supply chain breach.

Miasma Malware Targets npm, GitHub in Expanded Supply Chain Attack

Over 550 GitHub repositories have been compromised in a massive supply-chain attack, with malware harvesting developer credentials and spreading across package registries and workflows. The attack has already infected numerous npm packages and one Go module, putting developer data at risk.

Analyst 207
Rows of computer servers and networking equipment fill a brightly-lit network operations center, conveying a sense of…

FortiBleed Exposes 110 Million Credentials in Global Firewall Hack

A recent global firewall hack, dubbed FortiBleed, has exposed a staggering 110 million credentials, putting countless individuals and organizations at risk. This massive breach was made possible by a sophisticated five-stage pipeline that allowed hackers to capture sensitive information, including cleartext and hashed credentials, from compromised devices.

Analyst 207
Cramped, dimly lit room with cluttered desk, laptop, and scattered papers, surrounded by old computer equipment.

Threat Actors Monetize Stolen Credentials with Searchable Underground Services

Cybercriminals are cashing in on stolen credentials with a new breed of underground services that allow buyers to search and purchase specific, verified login details. This emerging market acts as a middleman between hackers who steal sensitive info and those who want to use it to take over accounts.

Analyst 207
Brightly lit coding workspace with laptop showing GitHub/GitLab page surrounded by coding materials and documents.

North Korean Hackers Exploit Coding Lures to Steal Crypto Credentials

In a sneaky move, North Korean hackers sent over 250 emails with innocent-looking coding tasks to nearly 100 US-based organizations, tricking them into handing over cryptocurrency credentials. The clever phishing scam, tracked as UNK_DeadDrop, targeted tech, education, and finance firms, with a special focus on cryptocurrency companies.

Analyst 207
A laptop with a blank screen sits amidst scattered papers and generic development tools in a well-lit workspace.

IronWorm Malware Infects 36 npm Packages in Supply-Chain Attack

Meet IronWorm, a sneaky Rust-based infostealer that's infected 36 npm packages, putting a wide range of sensitive credentials and secrets at risk of being harvested. This stealthy malware operates undetected, targeting everything from AWS and OpenAI credentials to cryptocurrency wallet files.

Analyst 207
Dimly lit server room with rows of computer servers and a blurred technician screen.

Hackers Exploit Active Directory Flaw to Harvest Passwords

Storing passwords in Active Directory description fields is a rookie mistake that hackers are eager to exploit, and one hacker did just that with alarming ease. It was disturbingly simple for them to get their hands on sensitive information.

Analyst 207
Developer workstation with open laptop showing code, surrounded by empty coffee cups and scattered notes, hinting at a…

Miasma Supply Chain Attack Targets Red Hat npm Packages

A new supply-chain campaign, codenamed Miasma, has compromised multiple Red Hat npm packages to steal sensitive credentials and deliver a self-propagating worm, putting developer machines at risk. This sneaky attack uses clever tactics like install-time execution and encrypted exfiltration to harvest secrets and spread its reach.

Analyst 207
Cryptocurrency developer's workspace with Mac computer, notes, and empty coffee cups.

Jinx-0164 Targets Crypto Developers with Custom macOS Malware

Beware of fake meetings on LinkedIn - cyber attackers are using them to trick crypto developers into installing custom macOS malware called Audiofix, which can steal sensitive info like passwords, SSH keys, and cryptocurrency wallet details. This sneaky malware is disguised as an audio fix, but its real goal is to harvest your valuable data.

Analyst 207
Close-up of computer circuit board with exposed casing revealing abstract malicious code in background.

MuddyWater Exploits DLL Side-Loading in Global Espionage Push

MuddyWater hackers have launched a massive global espionage campaign, infiltrating at least nine organizations across four continents by cleverly disguising malicious code as legitimate software. They used a sneaky trick called DLL side-loading to quietly steal credentials and browser data.

Analyst 207