Credential Leaks Intelligence
Infostealer malware campaigns (Lumma, RedLine, Vidar, StealC), combo list releases on dark web forums, credential stuffing operations, and enterprise exposure reports.
Credential Leaks — Archive & Latest
Blind Eagle (APT-C-36) Evolved Toolkit: AsyncRAT, njRAT & LimeRAT via AutoIt RunPE and DuckDNS C2 — OTX Detection Pack
Blind Eagle (APT-C-36) fields evolved AsyncRAT/njRAT toolkit — VBScript droppers, AutoIt RunPE loaders, DuckDNS C2 — targeting Colombian finance. High urgency.
NadMesh Botnet: Go-Based AI Infrastructure Credential Harvester — OTX Pulse Analysis & Enterprise Detection Pack
NadMesh, an industrial-grade Go botnet, is autonomously exploiting AI/cloud infrastructure (Redis, Docker, Kubernetes, MCP) across 90+ cloud provider ranges. Immediate IOC blocking and credential rotation advised.
Lua Loader Infostealer Campaign + GoSerpent APT Backdoor: OTX Pulse Analysis — Agent Tesla, XWorm & Southeast Asia Government Targeting Detection Pack
OTX pulses expose a global Lua-loader phishing campaign dropping Agent Tesla, Remcos, XWorm, and Snake Keylogger, plus TetrisPhantom's GoSerpent RAT hitting SE Asian governments. High urgency.
Starland RAT + WLDR Implant & Spirals Ransomware: OTX Pulse Analysis — UAT-11795 ClickFix Campaign and Rust-Based Double Extortion Detection Pack
OTX pulses reveal UAT-11795's Starland RAT/WLDR ClickFix campaign targeting US/EU credentials and crypto, plus novel Rust-based Spirals ransomware hitting Asian IT firms. Act now.
Tomorrowland 2026 Fake Ticket Shop Network: Phishing & Payment Fraud Infrastructure — OTX Pulse Analysis and Detection Pack
~12 fraudulent domains impersonating Tomorrowland 2026 target ticket seekers in EU with phishing, payment fraud & fake biometric checks. Urgent blocking advised.
Miasma Worm v3 npm Supply-Chain Attack + Tomorrowland Credential-Harvesting Scam Network: OTX Pulse Analysis — Detection Pack
OTX pulses expose Miasma v3 worm delivered via hijacked AsyncAPI npm packages and a 12-domain Tomorrowland phishing ring harvesting credentials and payments across the EU. Hunt now.
PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Espionage + Linux Botnet Credential Theft — OTX Detection Pack
OTX pulses expose PATCHCORD backdoor hitting Afghan telecom, Evooo1Bot Linux botnet, Miasma v3 npm supply-chain worm & Tomorrowland phishing. Full detection pack.
Multi-Stage Phishing Relay Chains + Tomorrowland 2026 Festival Fraud: Cloudflare Workers Abuse, HTML Smuggling & Typosquat Campaign — OTX Detection Pack
OTX pulses reveal multi-stage phishing chains abusing Cloudflare Workers/Framer with HTML smuggling, plus a dozen typosquat domains running fake Tomorrowland 2026 ticket scams. Block now.
Kratos PhaaS, Multi-Stage Redirect Chains & Festival Ticket Fraud: OTX Pulse Analysis — M365 Credential Theft Detection Pack
Kratos PhaaS kit, Cloudflare Workers/Framer redirect chains, and fake Tomorrowland ticket shops are harvesting M365 and payment credentials across US/EU. Urgent: hunt now.
Armored Likho Still Toolkit (Rust) + Multi-Stage Phishing Relay Chains: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose Armored Likho's Rust-based Still Toolkit targeting Telegram & audio surveillance, plus multi-stage phishing relays abusing Cloudflare Workers. High urgency.
CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack
OTX pulses expose Midnight Blizzard's hotel Wi-Fi captive portal credential theft (CornFlake/ChocoShell) and UNC6671's multi-brand vishing extortion. Urgent: block IOCs, reset M365 creds.
Aeternum Blockchain C2, ErrTraffic ClickFix, CaptiveCrunch M365 Phishing, GoldDigger Android: OTX Enterprise Detection Pack
OTX pulses reveal blockchain-C2 infostealers, ClickFix/EtherHiding loaders, hotel captive-portal M365 credential phishing, and GoldDigger Android banking trojan activity. High urgency for identity and endpoint hunting.
Midnight Blizzard CaptiveCrunch, codemado AiTM Phishing Stack, GhostDesk Spyware & WP-SHELLSTORM Webshell Botnet: OTX Pulse Analysis — Credential Theft Detection Pack
Live OTX pulses expose APT29 hotel Wi-Fi credential theft, a triple-operator AiTM phishing platform, fake CCleaner Chrome spyware, and 1.4M WordPress webshell campaign. Critical urgency.
Abyssos Modular RAT: LLVM-Obfuscated Credential Theft and VNC Access — OTX Pulse Detection Pack
New Abyssos modular RAT identified with LLVM obfuscation, credential theft, file exfiltration, and VNC access. C2 IPs and SHA256 hashes published. Urgency: HIGH.
Powercat Infostealer Campaign: Fake Game Cheats Deliver Discord Session Hijacking & Crypto Theft — OTX Pulse Analysis
Powercat infostealer spreads via fake Roblox/Minecraft/GTA V cheats, hijacking Discord sessions and stealing crypto wallets. Multi-stage Java loader. High urgency for enterprise endpoints.
NUL1DROPPER Slopsquatting Campaign + ChainDrop npm Worm: OTX Pulse Analysis — Supply Chain Credential Theft Detection Pack
OTX pulses reveal two active npm supply chain campaigns — AI-driven slopsquatting dropping Sliver RATs and the self-propagating ChainDrop worm — targeting developer credentials. High urgency.
SilverFox, Amaranth-Dragon & Lotus Blossom Converge on Indonesian BFSI: ValleyRAT, Amaranth Loader & Havoc C2 Detection Pack
OTX pulse: eight APT clusters targeting Indonesia's BFSI sector with ValleyRAT, Amaranth Loader, LOTUSLITE, Havoc and RustSL. Underground breach data in circulation. High urgency.
Vanta Stealer: Python-Based Cross-Platform Infostealer Targets Browser Credentials, Discord Tokens & Crypto Wallets — OTX Detection Pack
OTX pulse exposes Vanta Stealer, a PyArmor-obfuscated Python infostealer harvesting Chromium credentials, Discord/Telegram tokens, gaming accounts & crypto wallets. Hunt now.
Vidar/XMRig Factory-v3, Vanta, MacSync ClickFix, UNC6671 Vishing and Storm-2755 AiTM: OTX Credential-Theft Detection Pack
OTX pulses flag Vidar/XMRig malvertising, Vanta and MacSync stealers, UNC6671 vishing/AiTM and Storm-2755 M365 payroll BEC. Credential theft risk: high.
Larva-26005 (North Korea) Xctdoor Backdoor Campaign: CRAT Lineage, DLL Side-Loading & Ngrok C2 — OTX Enterprise Detection Pack
DPRK-linked Larva-26005 distributes Xctdoor backdoors via spear-phished LNK files and fake security installers, targeting Korean defense & tech orgs. Hunt and block now.
keyv & cacheable npm Supply Chain Compromise: Self-Propagating Cloud Credential Theft — OTX Pulse Analysis & Enterprise Detection Pack
Active npm supply chain attack via compromised keyv/cacheable packages deploys self-propagating cloud credential stealers through preinstall hooks. Tens of millions of weekly downloads affected. Immediate action required.
npm Supply Chain Compromise: keyv & cacheable Packages Poisoned with Ethereum C2 Credential Stealer — OTX Pulse Analysis
Active npm supply chain attack hits keyv/cacheable (tens of millions of weekly downloads). Malicious preinstall hooks steal cloud credentials via Ethereum-contract C2. Hunt now.
Powercat Java Stealer via Fake Xeno Roblox Cheats + keyv/cacheable npm Supply Chain Compromise: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose two credential-theft campaigns: Powercat Java stealer disguised as Roblox cheats, and a self-propagating npm supply chain worm targeting cloud credentials. High urgency.
Supply Chain & Blockchain C2: Shai-Hulud, SmartLoader, and EtherRAT Campaigns — OTX Analysis
Active npm supply chain (Shai-Hulud) and blockchain C2 (EtherRAT/SmartLoader) campaigns target devs & finance. Urgent IOCs included.
ClickFix Campaign: Starland RAT + WLDR Framework Targeting US Financial Sector — OTX Intelligence Briefing
Russian-speaking UAT-11795 deploying trojanized installers for Starland RAT & WLDR framework. US finance sector targeted. CRITICAL urgency.
Larva-24009 (HeptaX) Phishing: QuasarRAT & UltraVNC via LNK — OTX Pulse Analysis
Active Larva-24009 campaign targets Healthcare with QuasarRAT/UltraVNC via phishing LNKs. High urgency.
EvilProxy AiTM Campaign: Procurement Lures & Credential Theft — OTX Pulse Analysis
Active AiTM campaign targets education/gov with procurement lures using EvilProxy for MFA bypass and credential theft. High urgency.
InterlockRAT, Rhysida Ransomware, and Procurement AiTM Phishing: OTX Pulse Analysis
OTX alerts highlight Hive0163 InterlockRAT and Rhysida ransomware operations alongside a global procurement-themed AiTM phishing campaign stealing credentials.
Gaming Platform Credential Harvesting: Roblox/Minecraft Phishing Ecosystem — OTX Pulse Analysis
Active credential harvesting campaign targeting children via Roblox/Minecraft phishing sites and offerwall schemes.
Armored Likho's BusySnake Stealer & Gaming Platform Phishing: OTX Pulse Analysis — Enterprise Detection Pack
APT group Armored Likho deploys Python-based BusySnake Stealer against governments and energy sectors, while children's gaming credentials harvested via phishing. High urgency.
RedLine Stealer C2 Pivot & Toy Ghouls GenieLocker: Maritime Credential Theft & Manufacturing Ransomware
Active RedLine/Formbook credential theft cluster targeting maritime sector; new GenieLocker ransomware from Toy Ghouls hitting manufacturing. High urgency.
Infostealer Surge: Tax Season Phishing in India & PasasteSinTAG Domain Rotation
Active credential theft campaigns target India & Chile via WhatsApp tax scams and mass domain rotation. Immediate blocking required.
Phantom Stealer, Ousaban & OctLurk: Global Infostealer & Espionage Operations — OTX Pulse Analysis
OTX alerts to active infostealer campaigns: Phantom Stealer using steganography, Ousaban banking trojan in Iberia, and OctLurk espionage in Central Asia.
MacSync Stealer, Phantom Infostealer & Global Phishing Surge: OTX Pulse Analysis
Active credential theft campaigns detected: MacSync (macOS), Phantom Stealer (Windows), and mass phishing targeting India and Chile taxpayers.
ClickFix WebDAV Execution & PasasteSinTAG Phishing Surge: OTX Pulse Analysis — Credential Theft Infrastructure
OTX Alert: Active ClickFix WebDAV attacks and massive PasasteSinTAG phishing wave targeting Chile. Block domains now.
Shai-Hulud NPM Worm & ClickFix WebDAV: OTX Pulse Analysis — Enterprise Detection Pack
Active NPM supply chain attacks and ClickFix campaigns targeting GitHub/AWS credentials. Urgent detection engineering required.
Multi-Vector Credential Theft: Malicious VPN Extensions, NPM Worms, and Phishing Infrastructure — OTX Pulse Analysis
Credential theft surge via malicious VPN browser updates, NPM supply chain worms, and Chilean phishing. Urgent hunt required.
RMM Exploitation & Supply Chain Worms: TaskWeaver, Djinn Stealer, and npm Attacks
Active credential theft targeting devs via npm worms, SimpleHelp RMM exploits (CVE-2026-48558), and evolving ClickFix. High urgency.
Bumblebee, npm Supply Chain, and ClickFix: OTX Pulse Analysis — Credential Theft & Akira Ransomware
Active campaigns via SEO poisoning, npm worms, and ClickFix targeting admins/developers for credential theft and Akira ransomware.
Flying Eagle RAT, Shai-Hulud NPM Worm & ClickFix: Cross-Vector Credential Theft Campaigns — Detection Pack
Active infostealer campaigns targeting finance & dev environments via Android RAT, supply chain attacks, and WebDAV social engineering.
NagaPocker Mobile Credential Theft Campaign: QR Code Phishing Attacks Targeting Ukraine
Active mobile credential theft campaign using QR code phishing targeting Ukrainian financial sector with 11K+ daily detections.
AI Agent LLMjacking & QR Code Phishing: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal active exploitation of AI Model Context Protocol for credential theft and QR code phishing campaigns targeting financial sectors.
CastleLoader, NeedleStealer & AI MCP Exploits: Multi-Vector Credential Theft — OTX Pulse Analysis
Active campaigns deploying CastleLoader/NeedleStealer and exploiting AI infrastructure alongside QR-based mobile phishing for credential harvesting.
Fake Corepack Supply Chain Attack: OpenShield & Apprunner Distribution
Fake Corepack site targeting developers with OpenShield infostealer and Apprunner proxyware via typosquatting. Urgent blocking required.
Langflow AI Pipeline Exploitation (CVE-2026-55255): Chained RCE & IDOR Credential Theft
Active exploitation of Langflow via chained RCE and IDOR vulnerabilities results in credential theft and botnet deployment.
Kimsuky's KimJongRAT & Langflow Exploitation: OTX Pulse Analysis — Enterprise Detection Pack
Kimsuky abuses GitHub for KimJongRAT attacks; Langflow CVEs facilitate credential theft. High urgency.
Supply Chain Compromise: Klue to LastPass OAuth Token Theft — CRM Data Breach
LastPass CRM data exposed via Klue vendor compromise using stolen OAuth tokens. Urgency: High.
GitHub Actions Abuse & Supply Chain OAuth Theft: cPanel Exploit & CRM Data Breach
OTX Alert: GitHub Actions abuse powers cPanel exploitation while supply chain OAuth theft exposes LastPass CRM data.
Cisco SD-WAN Zero-Day & GitHub Actions Abuse: Supply Chain Credential Theft
Critical OTX pulses reveal CVE-2026-20245 and GitHub Actions abuse targeting enterprise credentials, OAuth tokens, and CRM data.
Prinz Eugen Ransomware & GitHub Actions Abuse: OTX Pulse Analysis — Enterprise Detection Pack
ROOTBOY deploys Prinz Eugen ransomware; massive GitHub Actions supply chain attack targeting cPanel; LastPass supply chain breach.
Showing 50 of 326 reports. Archive expands automatically as new intel is generated.
Every Credential LeaksReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.