Dark Side Intelligence Category

Credential Leaks Intelligence

Infostealer malware campaigns (Lumma, RedLine, Vidar, StealC), combo list releases on dark web forums, credential stuffing operations, and enterprise exposure reports.

363 reports availableRefreshed every 5 minutes

Credential Leaks — Archive & Latest

50 reports loaded
Credential Leaks

UNC6671 Multi-Brand Vishing Extortion: Okta-Themed AiTM Phishing Infrastructure — OTX Pulse Detection Pack

UNC6671 vishing crews pose as IT helpdesk to push Okta/passkey spoof portals, bypassing MFA via AiTM. Financial services & enterprise cloud targets. Hunt now.

Sep 6, 2026
Read →
Credential Leaks

MacSync Stealer + ClickFix Fake CAPTCHA Campaign: OTX Pulse Analysis — macOS Credential & Crypto Wallet Detection Pack

MacSync infostealer targeting macOS via ClickFix fake-CAPTCHA social engineering. Harvests browser credentials and crypto wallets. C2 infrastructure live. Hunt now.

Sep 5, 2026
Read →
Credential Leaks

SmartLoader NodeJS Infostealer + SecFlow AI-Orchestrated Intrusions: OTX Pulse Analysis — Enterprise Detection Pack

Fake AI GitHub repos deploy SmartLoader/NodeJS infostealer via blockchain C2; Chinese operator uses SecFlow AI agents against Asian gov/edu networks. HIGH urgency.

Sep 4, 2026
Read →
Credential Leaks

The Gentlemen Ransomware Group — TukTuk C2 v2.0 Framework & EDRKiller BYOVD Toolkit: OTX Pulse Analysis + Enterprise Detection Pack

OTX pulse exposes The Gentlemen's TukTuk C2 v2.0 framework with cross-platform agents and EDR-neutralization toolkit targeting US defense, healthcare, and aerospace. Hunt and block now.

Sep 3, 2026
Read →
Credential Leaks

Woodgnat Node.js Abuse Campaign: ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix — OTX Detection Pack

Woodgnat actor abuses signed node.exe to run ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix lures. 180 IOCs, EtherHiding C2. Immediate hunt required.

Sep 3, 2026
Read →
Credential Leaks

Tampered Exodus Wallet Installer Drops Modular RAT: Dll4 Suite Credential Theft Campaign — OTX Detection Pack

Fake Exodus crypto wallet installers are deploying a six-module RAT (Dll4_*) via JavaScript droppers and Azure Table Storage C2. High urgency — hunt now.

Sep 3, 2026
Read →
Credential Leaks

Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack

OTX pulses detail M365 AiTM session-token phishing and a fake Exodus wallet modular RAT using Azure-backed C2. Enterprise identity and crypto-adjacent users face elevated credential-theft risk.

Sep 2, 2026
Read →
Credential Leaks

Zer0day Stealer, StreamRat, Knight Office AiTM + Exodus RAT: OTX Credential-Theft Detection Pack

OTX flags AiTM M365 token theft, Android banking takeover, Rust infostealer/RAT pipeline and trojanized Exodus RAT; reset credentials now.

Sep 2, 2026
Read →
Credential Leaks

Sality Botnet Sinkhole & Tampered Exodus Wallet Modular RAT: OTX Pulse Analysis — Infostealer & Credential Theft Detection Pack

OTX pulses reveal the Sality P2P botnet takedown (EggJagger clipper delivery) and a modular RAT hidden in fake Exodus wallet installers. Credential and crypto theft at scale. Urgent.

Sep 2, 2026
Read →
Credential Leaks

Packagist Supply-Chain iOS Spyware Chain (CVE-2025-31277 / CVE-2025-43529): FunNULL-Linked Crypto Seed Theft — OTX Pulse Analysis

13 malicious Packagist Composer themes inject JS delivering iOS WebKit-to-kernel spyware that steals crypto wallet seeds. FunNULL infrastructure implicated. URGENT.

Sep 1, 2026
Read →
Credential Leaks

BraZetsu IAB Framework & Packagist iOS Spyware Chain: OTX Pulse Analysis — Exilware Initial Access + Supply Chain Credential Theft Detection Pack

OTX pulses expose Exilware's BraZetsu Python IAB framework targeting LATAM/Iberian finance, plus 13 malicious Packagist themes weaponizing iOS WebKit CVEs for crypto seed theft. Urgent hunt advised.

Sep 1, 2026
Read →
Credential Leaks

JSCeal V8 Bytecode Cryptocurrency Stealer: Compiled Node.js Infostealer Evading Static Analysis — OTX Pulse Detection Pack

OTX pulse exposes JSCeal, a cryptocurrency-focused infostealer shipped as compiled V8 bytecode with RC4 string encryption, control-flow flattening, and MITM browser theft. High urgency for SOC hunting.

Aug 31, 2026
Read →
Credential Leaks

Blind Eagle (APT-C-36) GitHub Loader Pipeline: AsyncRAT, DcRat, Remcos & XWorm Targeting Colombian Government — OTX Detection Pack

OTX pulse exposes Blind Eagle operator staging AsyncRAT, DcRat, Remcos & XWorm via GitHub loaders against Colombian government. IOCs + Sigma/KQL detections inside.

Aug 31, 2026
Read →
Credential Leaks

AnonyMousKIT AI-Powered PhaaS Supply Chain: OTX Pulse Analysis — Apple Activation Lock Credential Harvesting Detection Pack

AnonyMousKIT PhaaS platform uses AI vishing and multi-channel phishing across 506 domains to steal Apple credentials and disable Activation Lock. High urgency for government and education sectors.

Aug 29, 2026
Read →
Credential Leaks

DARKLANTERN/SPEAKINGSTONE Implants, Evilginx AiTM & AnonyMousKIT PhaaS: OTX Credential-Theft Detection Pack

OTX pulses expose converging credential theft: malicious browser extensions, ZBT firmware implants, AI PhaaS and Evilginx AiTM. Block IOCs, reset exposed sessions, harden edge now.

Aug 29, 2026
Read →
Credential Leaks

Dysphoria Blockchain-C2 Botnet, Browser-Extension Wallet Drainers & AnonyMousKIT PhaaS: OTX Credential-Theft Campaign Analysis — Enterprise Detection Pack

OTX exposes converging credential-theft ops: Dysphoria botnet, 19 wallet-draining browser extensions, ZBT implants, and AnonyMousKIT PhaaS. Hunt immediately.

Aug 29, 2026
Read →
Credential Leaks

pepesoft.exe Infostealer + ZBT Firmware Implants + XenoRAT Spear-Phishing: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal NuGet supply-chain infostealers, ZBT router firmware backdoors, Kimsuky XenoRAT campaigns, and browser wallet drainers. Immediate IOC blocking and credential rotation required.

Aug 28, 2026
Read →
Credential Leaks

DEV#POPPER npm Supply Chain RAT, SectopRAT Fake Claude Installers & 19-Extension Wallet Drainer: OTX Pulse Analysis — Blockchain C2 & Credential Theft Detection Pack

OTX pulses reveal npm supply-chain RAT delivery, malvertised fake Claude Desktop installers, and 19 malicious browser extensions — all stealing credentials via blockchain-backed C2. URGENT.

Aug 28, 2026
Read →
Credential Leaks

CastleLoader/NeedleStealer, MCP AI-Agent Exploitation and RecruitTrap Mobile OAuth Theft: OTX Enterprise Detection Pack

OTX pulses show credential-theft convergence: CastleLoader/NeedleStealer chains, MCP honeypot abuse, and RecruitTrap mobile OAuth phishing. Enterprise identity and browser secrets are at immediate risk.

Aug 26, 2026
Read →
Credential Leaks

GoCaracal + Bandook C2, MCP Secrets Abuse, and RecruitTrap OAuth Phishing: OTX Pulse Detection Pack — 2026-08-26

OTX shows converged credential theft: Dark Caracal espionage in LatAm telecom, MCP/AI-agent secrets abuse, and RecruitTrap mobile OAuth phishing. Hunt and block now.

Aug 26, 2026
Read →
Credential Leaks

AMOS Stealer EtherHiding C2, EKZ Stealer via Fortinet CVE-2026-35616 & RecruitTrap OAuth Phishing: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal AMOS/XMRig macOS ClickFix campaign with blockchain C2, EKZ Stealer deployed via Fortinet EMS CVE-2026-35616, and RecruitTrap credential phishing. Enterprise detection pack included.

Aug 26, 2026
Read →
Credential Leaks

Rhadamanthys Stealer + RecruitTrap Phishing Kit: OTX Pulse Analysis — AI-Generated Malware & OAuth Token Theft Detection Pack

OTX pulses reveal AI-assisted infostealers (Rhadamanthys, Oyster) reaching endpoints and RecruitTrap recruitment phishing harvesting enterprise OAuth tokens on mobile. High urgency.

Aug 25, 2026
Read →
Credential Leaks

Vidar Infostealer via Fake GTA 6 Lures, HookBot/ERMAC Leak Fallout & RecruitTrap OAuth Phishing: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses flag Vidar stealer in fake GTA 6 demo sites, HookBot/ERMAC source-leak panels, and RecruitTrap OAuth phishing hitting enterprise credentials. Hunt now.

Aug 25, 2026
Read →
Credential Leaks

SysScan Fake AV Scam Network + RecruitTrap Mobile Credential Phishing: OTX Pulse Analysis — Enterprise Detection Pack

Two concurrent social-engineering campaigns — SysScan fake security scans and RecruitTrap recruitment phishing — are stripping endpoint defenses and harvesting enterprise credentials. Hunt now.

Aug 25, 2026
Read →
Credential Leaks

Education Sector Credential Harvesting Surge: Typosquat Phishing Infrastructure Targeting Students — OTX Pulse Analysis & Detection Pack

4,696 weekly attacks per education org; typosquat phishing domains harvesting student credentials. High urgency for EDU, gov, retail sectors.

Aug 23, 2026
Read →
Credential Leaks

IOCONTROL + MALPDB PLC Sabotage Campaign & Education Credential-Phishing Surge: OTX Pulse Analysis — Enterprise Detection Pack

Cyber Av3ngers exploiting internet-exposed PLCs via legitimate engineering software; parallel phishing surge hitting education with 4,696 weekly attacks. Critical urgency for OT/energy and EDU sectors.

Aug 23, 2026
Read →
Credential Leaks

BRIDGEHEAD npm Typosquat + proc-macro1 Rust Crate Compromise: Supply-Chain Credential Theft Campaign — OTX Detection Pack

OTX pulses reveal twin supply-chain infostealer ops: 40 typosquatted npm packages and compromised Rust crates delivering in-memory crypto-wallet and credential stealers.

Aug 22, 2026
Read →
Credential Leaks

Hermes AI-Driven Espionage, N4D go-titan & Supply Chain Credential Theft: OTX Pulse Detection Pack

Autonomous AI attack agent Hades targets Thai finance ministry; npm/Rust typosquats and Void Blizzard Zimbra zero-click phishing drive credential theft at scale. HIGH urgency.

Aug 22, 2026
Read →
Credential Leaks

FakeAgent Malvertising + SectopRAT/StealC, npm/Rust Supply Chain Stealers & N4D Mesh Controller: OTX Pulse Analysis — Enterprise Detection Pack

CRITICAL: Claude AI malvertising delivers SectopRAT/StealC to 29 orgs; npm & Rust crates compromised for credential theft; N4D botnet exploits MCP servers. Block IOCs now.

Aug 22, 2026
Read →
Credential Leaks

SynkLoader, BRIDGEHEAD & N4D Mesh: Cross-Platform Credential Theft Wave — OTX Pulse Analysis & Enterprise Detection Pack

OTX pulses reveal converging credential-theft campaigns: Teams-phished SynkLoader, npm/Rust supply-chain stealers, and N4D/NadMesh botnets hunting AI infrastructure keys. High urgency.

Aug 21, 2026
Read →
Credential Leaks

AMOS Stealer, N4D Mesh Controller & 'BRIDGEHEAD' npm Campaign: OTX Pulse Analysis — Infostealer Detection Pack for Enterprise SOCs

OTX pulses reveal five active credential-theft campaigns: ClickFix macOS stealers, npm typosquatting, N4D Linux malware, malicious Firefox extensions, and education phishing. URGENT: hunt now.

Aug 20, 2026
Read →
Credential Leaks

Operation STANDOFF + Offside Wallet Theft Factory: GitHub-Redirected C2, Stealer Loader Chains & Malicious Firefox Extensions — OTX Enterprise Detection Pack

OTX reveals two active campaigns: Operation STANDOFF's Russian-speaking loader distributing Raccoon/RedLine/Amadey via GitHub-redirected C2, and 77 malicious Firefox extensions stealing crypto wallets and credentials. Immediate hunting required.

Aug 20, 2026
Read →
Credential Leaks

ClickFix Fileless Infostealers, JADEPUFFER AI-Targeting Ransomware & Balonx PhaaS: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal ClickFix fake-CAPTCHA infostealer evolution, JADEPUFFER's AI-destroying ENCFORGE ransomware, Mexican banking PhaaS, and 77 malicious Firefox extensions. HIGH urgency — credential theft at scale.

Aug 20, 2026
Read →
Credential Leaks

Mirage2FA AitM Phishing-as-a-Service: Microsoft 365 Session Hijacking Campaign (LinX Coders) — OTX Detection Pack

Mirage2FA PhaaS kit hijacks Microsoft 365 sessions via AitM proxying & HTML smuggling — 4K+ US victims. IOCs, Sigma, KQL and hunt scripts inside.

Aug 19, 2026
Read →
Credential Leaks

ClickFix RAT MaaS, Kimsuky Gomir Variants & Mirage2FA AiTM Phishing: OTX Pulse Analysis — Enterprise Detection Pack

LIVE OTX: ClickFix-delivered NodeJS RAT over Tor gRPC, Kimsuky BirdTroy/DriveTroy supply-chain intrusions, and Mirage2FA AiTM phishing hitting 4K+ US M365 tenants.

Aug 19, 2026
Read →
Credential Leaks

PhantomStealer Injector + Mirage2FA AitM PhaaS: OTX Pulse Analysis — Credential Theft Detection Pack

OTX pulses reveal PhantomStealer UAC-bypass injectors via quote-phishing and Mirage2FA AitM kit hijacking 4K+ M365 sessions. Hunt and block now.

Aug 19, 2026
Read →
Credential Leaks

Octagon Android Banking Bot (MaaS): AndroidKitKat's Crypto-Stealing Trojan — OTX Pulse Analysis & Detection Pack

Octagon, a $1,400/month Android MaaS fraud bot from AndroidKitKat, targets crypto wallets and banking apps via accessibility abuse, HVNC, and overlays.

Aug 18, 2026
Read →
Credential Leaks

Blind Eagle (APT-C-36) Evolved Toolkit: AsyncRAT, njRAT & LimeRAT via AutoIt RunPE and DuckDNS C2 — OTX Detection Pack

Blind Eagle (APT-C-36) fields evolved AsyncRAT/njRAT toolkit — VBScript droppers, AutoIt RunPE loaders, DuckDNS C2 — targeting Colombian finance. High urgency.

Aug 17, 2026
Read →
Credential Leaks

NadMesh Botnet: Go-Based AI Infrastructure Credential Harvester — OTX Pulse Analysis & Enterprise Detection Pack

NadMesh, an industrial-grade Go botnet, is autonomously exploiting AI/cloud infrastructure (Redis, Docker, Kubernetes, MCP) across 90+ cloud provider ranges. Immediate IOC blocking and credential rotation advised.

Aug 16, 2026
Read →
Credential Leaks

Lua Loader Infostealer Campaign + GoSerpent APT Backdoor: OTX Pulse Analysis — Agent Tesla, XWorm & Southeast Asia Government Targeting Detection Pack

OTX pulses expose a global Lua-loader phishing campaign dropping Agent Tesla, Remcos, XWorm, and Snake Keylogger, plus TetrisPhantom's GoSerpent RAT hitting SE Asian governments. High urgency.

Aug 15, 2026
Read →
Credential Leaks

Starland RAT + WLDR Implant & Spirals Ransomware: OTX Pulse Analysis — UAT-11795 ClickFix Campaign and Rust-Based Double Extortion Detection Pack

OTX pulses reveal UAT-11795's Starland RAT/WLDR ClickFix campaign targeting US/EU credentials and crypto, plus novel Rust-based Spirals ransomware hitting Asian IT firms. Act now.

Aug 15, 2026
Read →
Credential Leaks

Tomorrowland 2026 Fake Ticket Shop Network: Phishing & Payment Fraud Infrastructure — OTX Pulse Analysis and Detection Pack

~12 fraudulent domains impersonating Tomorrowland 2026 target ticket seekers in EU with phishing, payment fraud & fake biometric checks. Urgent blocking advised.

Aug 14, 2026
Read →
Credential Leaks

Miasma Worm v3 npm Supply-Chain Attack + Tomorrowland Credential-Harvesting Scam Network: OTX Pulse Analysis — Detection Pack

OTX pulses expose Miasma v3 worm delivered via hijacked AsyncAPI npm packages and a 12-domain Tomorrowland phishing ring harvesting credentials and payments across the EU. Hunt now.

Aug 14, 2026
Read →
Credential Leaks

PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Espionage + Linux Botnet Credential Theft — OTX Detection Pack

OTX pulses expose PATCHCORD backdoor hitting Afghan telecom, Evooo1Bot Linux botnet, Miasma v3 npm supply-chain worm & Tomorrowland phishing. Full detection pack.

Aug 14, 2026
Read →
Credential Leaks

Multi-Stage Phishing Relay Chains + Tomorrowland 2026 Festival Fraud: Cloudflare Workers Abuse, HTML Smuggling & Typosquat Campaign — OTX Detection Pack

OTX pulses reveal multi-stage phishing chains abusing Cloudflare Workers/Framer with HTML smuggling, plus a dozen typosquat domains running fake Tomorrowland 2026 ticket scams. Block now.

Aug 13, 2026
Read →
Credential Leaks

Kratos PhaaS, Multi-Stage Redirect Chains & Festival Ticket Fraud: OTX Pulse Analysis — M365 Credential Theft Detection Pack

Kratos PhaaS kit, Cloudflare Workers/Framer redirect chains, and fake Tomorrowland ticket shops are harvesting M365 and payment credentials across US/EU. Urgent: hunt now.

Aug 13, 2026
Read →
Credential Leaks

Armored Likho Still Toolkit (Rust) + Multi-Stage Phishing Relay Chains: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose Armored Likho's Rust-based Still Toolkit targeting Telegram & audio surveillance, plus multi-stage phishing relays abusing Cloudflare Workers. High urgency.

Aug 13, 2026
Read →
Credential Leaks

CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack

OTX pulses expose Midnight Blizzard's hotel Wi-Fi captive portal credential theft (CornFlake/ChocoShell) and UNC6671's multi-brand vishing extortion. Urgent: block IOCs, reset M365 creds.

Aug 12, 2026
Read →
Credential Leaks

Aeternum Blockchain C2, ErrTraffic ClickFix, CaptiveCrunch M365 Phishing, GoldDigger Android: OTX Enterprise Detection Pack

OTX pulses reveal blockchain-C2 infostealers, ClickFix/EtherHiding loaders, hotel captive-portal M365 credential phishing, and GoldDigger Android banking trojan activity. High urgency for identity and endpoint hunting.

Aug 12, 2026
Read →
Credential Leaks

Midnight Blizzard CaptiveCrunch, codemado AiTM Phishing Stack, GhostDesk Spyware & WP-SHELLSTORM Webshell Botnet: OTX Pulse Analysis — Credential Theft Detection Pack

Live OTX pulses expose APT29 hotel Wi-Fi credential theft, a triple-operator AiTM phishing platform, fake CCleaner Chrome spyware, and 1.4M WordPress webshell campaign. Critical urgency.

Aug 12, 2026
Read →

Showing 50 of 363 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every Credential LeaksReport Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.