Credential Leaks Intelligence
Infostealer malware campaigns (Lumma, RedLine, Vidar, StealC), combo list releases on dark web forums, credential stuffing operations, and enterprise exposure reports.
Credential Leaks — Archive & Latest
DARKLANTERN, SPEAKINGSTONE & ENDLESSDOORS: ZBT Router Firmware Implants in the Global Supply Chain — OTX Pulse Analysis & Detection Pack
Three firmware implants embedded in ZBT routers expose root shell access via unauthenticated UDP 9992 backdoor. Global supply chain reach across 11 countries. Critical urgency.
AnonyMousKIT AI-Powered PhaaS Supply Chain: 506-Domain Apple Activation Lock Phishing Network — OTX Detection Pack
OTX exposes AnonyMousKIT, an AI-driven PhaaS with 506 domains harvesting Apple ID credentials via SMS, WhatsApp, email & vishing. Gov/Edu targeted. HIGH urgency.
Dark Caracal GoCaracal Framework + Russian Evilginx OAuth Phishing Clusters: OTX Pulse Analysis — Credential Theft Detection Pack
OTX pulses reveal Dark Caracal's new GoCaracal modular espionage framework targeting Latin America and Russian clusters (UNC6293/UNC7005/UNC5976) running Evilginx OAuth/device-code phishing against academia and government. High urgency — credential theft at scale.
RemotePanel + BoundSiphon: ClickFix-Delivered Dual-Payload Toolkit for Persistent Access & Browser Credential Theft — OTX Detection Pack
OTX pulse details two undocumented .NET payloads — RemotePanel HVNC RAT and BoundSiphon browser stealer — deployed via ClickFix chains with blockchain-based C2 resolution. Immediate credential rotation advised.
MacSync macOS Stealer + HookBot/ERMAC Android Banking Leak: OTX Pulse Analysis — Credential-Theft Detection Pack
OTX flags MacSync targeting macOS crypto users/devs and HookBot/ERMAC source leak enabling Android banking panel sprawl. Hunt now; credential exposure likely.
CARBONATO Docker Botnet + PavinLoader/Amatera Stealer: OTX Pulse Analysis — Exposed Daemon Exploitation & ClickFix Credential Theft Detection Pack
OTX pulses reveal CARBONATO botnet abusing exposed Docker daemons and PavinLoader delivering Amatera Stealer via ClickFix. Credential theft focus. High urgency.
SectopRAT via Fake Claude Desktop Installers: Bing Malvertising, EtherHiding C2 & DLL Sideloading — OTX Detection Pack
FakeAgent campaign pushes trojanized Claude Desktop installers via Bing malvertising, delivering SectopRAT through DLL sideloading, EtherHiding blockchain C2, and scheduled task persistence.
ClickFix AS202412 Infostealer Chains + Red Heron WordPress Raids: OTX Detection Pack for DarkGate, Amadey, Matanbuchus
OTX pulses: ClickFix fake-CAPTCHA chains on AS202412 and Red Heron WordPress/gov record theft; credential exposure high-block IOCs, hunt now.
DarkMe RAT, RemControl Banking Trojan & ClickFix Loader Chains: OTX Pulse Analysis — Credential Theft Detection Pack
OTX pulses reveal credential theft surge: Water Hydra's DarkMe RAT, RemControl Android banking trojan, ClickFix loader chains, and Red Heron WordPress exploitation. Act now.
Vidar Stealer VM-Based String Obfuscation & Custom ChaCha20-Style Ciphers: OTX Pulse Analysis — Enterprise Detection Pack
Vidar infostealer deploys bytecode VM and custom ARX stream ciphers to defeat string analysis. Credential theft at scale — hunt now, rotate exposed identities within 24h.
Typosquatted AI Platform Malware Distribution: 'claude.ai.download-app.us' Credential-Harvesting Campaign — OTX Detection Pack
OTX pulse confirms adversaries abusing trusted AI platform branding (claude.ai typosquats) to distribute credential-harvesting malware across 8 critical sectors. Hunt now.
Mirage2FA PhaaS Kit: Microsoft 365 Session Hijacking via AiTM — OTX Pulse Analysis & Detection Pack
Mirage2FA phishing-as-a-service kit hijacks Microsoft 365 sessions via AiTM attacks, 4K+ US victims. Blocking, hunting, and identity response guidance inside.
Mirage2FA AiTM PhaaS + T-Mobile Smishing Credential Campaigns: OTX Pulse Analysis — Session Hijack Detection Pack
OTX pulses flag Mirage2FA AiTM phishing-as-a-service hijacking M365 sessions (4K+ US victims) and a T-Mobile rewards smishing wave. Credential/session theft — hunt now.
Mirage2FA PhaaS, Offside Wallet Theft Factory & T-Mobile Smishing: OTX Pulse Analysis — Credential Theft Detection Pack
Three active credential-theft campaigns: Mirage2FA AiTM phishing hijacking M365 sessions (4K+ US victims), 77 malicious Firefox extensions stealing crypto wallets, and T-Mobile smishing.
Mirage2FA AiTM, Spyroid PhaaS, and DXSCAN Go C2: OTX Credential-Theft Detection Pack for M365, Banking, and Edge Exploits
Live OTX pulses show converging credential-theft campaigns: Mirage2FA AiTM M365 session theft, Spyroid PhaaS banking fraud, T-Mobile smishing, DXSCAN mass harvesting. Hunt now.
PolinRider Supply-Chain Infostealer, Clop LEMURLOOT Implant & Settra Ransomware: OTX Pulse Analysis — Credential Theft Detection Pack
OTX pulses reveal PolinRider supply-chain infostealer, Clop Windchill extortion implant, Settra ransomware via MeshAgent RMM, and a 16K-credential harvest. High urgency.
Operation RapidRust (APT36) + Mirage2FA AiTM Phishing Kit: Rust-Based Backdoors and M365 Session Theft — OTX Detection Pack
OTX pulses flag APT36's Operation RapidRust hitting India/Afghanistan gov & defense, and Mirage2FA AiTM phishing hijacking 4K+ M365 sessions. Urgent: hunt & block.
Octagon Android Banking Bot + Mirage2FA Session Hijacking + APT36 Operation RapidRust: OTX Pulse Analysis — Enterprise Credential Theft Detection Pack
OTX pulses reveal Octagon Android MaaS targeting crypto/banking apps, Mirage2FA AiTM phishing hijacking 4K+ Microsoft 365 sessions, and APT36's RapidRust toolkit hitting government targets. HIGH urgency.
VectraRAT MaaS Platform + APT36 Operation RapidRust: OTX Pulse Analysis — Infostealer & Espionage Detection Pack
OTX pulses expose VectraRAT MaaS (Amadey/Vidar delivery) and APT36's Rust-based RapidRust arsenal targeting finance, government, and defense. High urgency.
NightEagle APT GhostContainer Exchange Backdoor + AMOS macOS Stealer ClickFix Campaign: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose NightEagle (APT-Q-95) deploying GhostContainer on Russian Exchange servers and AMOS macOS stealer spreading via ClickFix — credential theft at scale. Act now.
CVE-2024-21762 FortiGate SSL-VPN Exploitation + MeshCentral RMM Persistence: Thai Telecom Intrusion — OTX Detection Pack
OTX pulse reveals active intrusion against Thai ISP 3BB via FortiGate CVE-2024-21762 exploit and MeshCentral RMM for covert C2. High urgency for edge device owners.
KATARU IoT Botnet + Mirai-Style DDoS: OTX Pulse Analysis — Telnet Brute-Force, Public Linux LPE Exploits, and Encrypted C2 Detection Pack
OTX flags KATARU IoT malware using Telnet brute-force, Mirai-style DDoS and public Linux LPE CVEs; hunt edge devices, cron persistence and C2 now.
PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Backdoors and Multi-Functional Linux Botnet — OTX Pulse Detection Pack
Two active campaigns: Operation C-Major's PATCHCORD/SHEETCORD cluster hitting Afghan telecom & South Asian critical infrastructure via Google Sheets C2, plus Evooo1Bot Linux botnet. High urgency.
Armored Likho 'Still Toolkit' Rust Espionage + Storm-3121 Passkey AiTM Phishing: OTX Pulse Analysis — Credential Theft Detection Pack
Armored Likho's Rust Still Toolkit spies on Russian gov/tech/edu orgs while Storm-3121 passkey AiTM phishing hijacks cloud identities. High urgency.
Storm-3121/Storm-3032 Passkey AiTM Phishing + AI-Driven PaperCut Exploitation: OTX Pulse Analysis — Identity & Credential Defense Pack
OTX pulses reveal Storm-3121/Storm-3032 passkey-themed AiTM phishing compromising cloud identities, plus AI-automated PaperCut exploitation (CVE-2026-81578/82078). Credential theft risk: HIGH.
Midnight Blizzard CaptiveCrunch, LegionLoader ClickFix & Passkey AiTM Campaigns: OTX Pulse Analysis — Identity Theft Detection Pack
OTX pulses expose UNC2452 hotel captive-portal M365 theft, ClickFix LegionLoader drops, passkey AiTM phishing, and LATAM banking trojans. Credential-focused orgs must act now.
njRAT/DCRAT, GhostDesk Chrome Spyware, PaperCut CVEs & Storm-3121 Passkey AiTM: OTX Credential-Theft Detection Pack
OTX pulses show SEO-poisoned GTA6 ISOs, fake CCleaner GhostDesk spyware, PaperCut exploitation and passkey AiTM driving credential/cloud theft. Hunt now.
UTA0560/JungleBamboo 0-day Chain, Djinn Stealer, Gigabud/Vwork & PaperCut AI Exploitation: OTX Enterprise Detection Pack
OTX pulses show converging credential-theft ops: Chrome/Windows 0-days, Djinn/TaskWeaver, GTA6 lure RATs, Gigabud/Vwork, and AI-scaled PaperCut exploitation. Act now.
Aeternum Blockchain C2 Botnet: XWorm, ZingoStealer and XMRig Loader Activity — OTX Detection Pack
OTX pulse flags LenAI-linked Aeternum loader using Polygon smart contracts as resilient C2, staging XWorm, ZingoStealer and XMRig. Hunt RPC endpoints, DNS and loader hashes now.
APT37 'Ted' Backdoor Linux Toolkit + Abyssos RAT: OTX Pulse Analysis — Infostealer Detection Pack
APT37 deploys trojanized HAProxy backdoor against South Korean media/auto; new Abyssos RAT steals credentials via VNC. Urgent hunt guidance inside.
Vidar VM-Obfuscated Stealer + ClearFake/Amatera WebDAV Chain (UAT-10820): OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal VM-obfuscated Vidar infostealer and UAT-10820's ClearFake/Amatera WebDAV chain hitting government targets in 7 countries. Credential theft at scale — hunt now.
BigBear 2.0 Evilginx2 PhaaS Campaign: AiTM Microsoft 365 Credential Theft — OTX Detection Pack
BigBear 2.0, an Evilginx2-based phishing-as-a-service run by 'General Boss', is stealing M365 credentials via AiTM across 42 Vultr VPS nodes. High urgency.
PEEP Browser RAT 'Smart Bookmarks' Chrome/Edge Backdoor: OTX Pulse Analysis — Enterprise Detection Pack
PEEP Chrome RAT poses as Smart Bookmarks, hijacks browser sessions and enables host command execution after admin compromise; hunt and block now.
UNC6671 Multi-Brand Vishing Extortion: Okta-Themed AiTM Phishing Infrastructure — OTX Pulse Detection Pack
UNC6671 vishing crews pose as IT helpdesk to push Okta/passkey spoof portals, bypassing MFA via AiTM. Financial services & enterprise cloud targets. Hunt now.
MacSync Stealer + ClickFix Fake CAPTCHA Campaign: OTX Pulse Analysis — macOS Credential & Crypto Wallet Detection Pack
MacSync infostealer targeting macOS via ClickFix fake-CAPTCHA social engineering. Harvests browser credentials and crypto wallets. C2 infrastructure live. Hunt now.
SmartLoader NodeJS Infostealer + SecFlow AI-Orchestrated Intrusions: OTX Pulse Analysis — Enterprise Detection Pack
Fake AI GitHub repos deploy SmartLoader/NodeJS infostealer via blockchain C2; Chinese operator uses SecFlow AI agents against Asian gov/edu networks. HIGH urgency.
The Gentlemen Ransomware Group — TukTuk C2 v2.0 Framework & EDRKiller BYOVD Toolkit: OTX Pulse Analysis + Enterprise Detection Pack
OTX pulse exposes The Gentlemen's TukTuk C2 v2.0 framework with cross-platform agents and EDR-neutralization toolkit targeting US defense, healthcare, and aerospace. Hunt and block now.
Woodgnat Node.js Abuse Campaign: ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix — OTX Detection Pack
Woodgnat actor abuses signed node.exe to run ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix lures. 180 IOCs, EtherHiding C2. Immediate hunt required.
Tampered Exodus Wallet Installer Drops Modular RAT: Dll4 Suite Credential Theft Campaign — OTX Detection Pack
Fake Exodus crypto wallet installers are deploying a six-module RAT (Dll4_*) via JavaScript droppers and Azure Table Storage C2. High urgency — hunt now.
Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack
OTX pulses detail M365 AiTM session-token phishing and a fake Exodus wallet modular RAT using Azure-backed C2. Enterprise identity and crypto-adjacent users face elevated credential-theft risk.
Zer0day Stealer, StreamRat, Knight Office AiTM + Exodus RAT: OTX Credential-Theft Detection Pack
OTX flags AiTM M365 token theft, Android banking takeover, Rust infostealer/RAT pipeline and trojanized Exodus RAT; reset credentials now.
Sality Botnet Sinkhole & Tampered Exodus Wallet Modular RAT: OTX Pulse Analysis — Infostealer & Credential Theft Detection Pack
OTX pulses reveal the Sality P2P botnet takedown (EggJagger clipper delivery) and a modular RAT hidden in fake Exodus wallet installers. Credential and crypto theft at scale. Urgent.
Packagist Supply-Chain iOS Spyware Chain (CVE-2025-31277 / CVE-2025-43529): FunNULL-Linked Crypto Seed Theft — OTX Pulse Analysis
13 malicious Packagist Composer themes inject JS delivering iOS WebKit-to-kernel spyware that steals crypto wallet seeds. FunNULL infrastructure implicated. URGENT.
BraZetsu IAB Framework & Packagist iOS Spyware Chain: OTX Pulse Analysis — Exilware Initial Access + Supply Chain Credential Theft Detection Pack
OTX pulses expose Exilware's BraZetsu Python IAB framework targeting LATAM/Iberian finance, plus 13 malicious Packagist themes weaponizing iOS WebKit CVEs for crypto seed theft. Urgent hunt advised.
JSCeal V8 Bytecode Cryptocurrency Stealer: Compiled Node.js Infostealer Evading Static Analysis — OTX Pulse Detection Pack
OTX pulse exposes JSCeal, a cryptocurrency-focused infostealer shipped as compiled V8 bytecode with RC4 string encryption, control-flow flattening, and MITM browser theft. High urgency for SOC hunting.
Blind Eagle (APT-C-36) GitHub Loader Pipeline: AsyncRAT, DcRat, Remcos & XWorm Targeting Colombian Government — OTX Detection Pack
OTX pulse exposes Blind Eagle operator staging AsyncRAT, DcRat, Remcos & XWorm via GitHub loaders against Colombian government. IOCs + Sigma/KQL detections inside.
AnonyMousKIT AI-Powered PhaaS Supply Chain: OTX Pulse Analysis — Apple Activation Lock Credential Harvesting Detection Pack
AnonyMousKIT PhaaS platform uses AI vishing and multi-channel phishing across 506 domains to steal Apple credentials and disable Activation Lock. High urgency for government and education sectors.
DARKLANTERN/SPEAKINGSTONE Implants, Evilginx AiTM & AnonyMousKIT PhaaS: OTX Credential-Theft Detection Pack
OTX pulses expose converging credential theft: malicious browser extensions, ZBT firmware implants, AI PhaaS and Evilginx AiTM. Block IOCs, reset exposed sessions, harden edge now.
Dysphoria Blockchain-C2 Botnet, Browser-Extension Wallet Drainers & AnonyMousKIT PhaaS: OTX Credential-Theft Campaign Analysis — Enterprise Detection Pack
OTX exposes converging credential-theft ops: Dysphoria botnet, 19 wallet-draining browser extensions, ZBT implants, and AnonyMousKIT PhaaS. Hunt immediately.
pepesoft.exe Infostealer + ZBT Firmware Implants + XenoRAT Spear-Phishing: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal NuGet supply-chain infostealers, ZBT router firmware backdoors, Kimsuky XenoRAT campaigns, and browser wallet drainers. Immediate IOC blocking and credential rotation required.
Showing 50 of 396 reports. Archive expands automatically as new intel is generated.
Every Credential Leaks Report Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.