Dark Side Intelligence Category

Credential Leaks Intelligence

Infostealer malware campaigns (Lumma, RedLine, Vidar, StealC), combo list releases on dark web forums, credential stuffing operations, and enterprise exposure reports.

326 reports availableRefreshed every 5 minutes

Credential Leaks — Archive & Latest

50 reports loaded
Credential Leaks

Blind Eagle (APT-C-36) Evolved Toolkit: AsyncRAT, njRAT & LimeRAT via AutoIt RunPE and DuckDNS C2 — OTX Detection Pack

Blind Eagle (APT-C-36) fields evolved AsyncRAT/njRAT toolkit — VBScript droppers, AutoIt RunPE loaders, DuckDNS C2 — targeting Colombian finance. High urgency.

Aug 17, 2026
Read →
Credential Leaks

NadMesh Botnet: Go-Based AI Infrastructure Credential Harvester — OTX Pulse Analysis & Enterprise Detection Pack

NadMesh, an industrial-grade Go botnet, is autonomously exploiting AI/cloud infrastructure (Redis, Docker, Kubernetes, MCP) across 90+ cloud provider ranges. Immediate IOC blocking and credential rotation advised.

Aug 16, 2026
Read →
Credential Leaks

Lua Loader Infostealer Campaign + GoSerpent APT Backdoor: OTX Pulse Analysis — Agent Tesla, XWorm & Southeast Asia Government Targeting Detection Pack

OTX pulses expose a global Lua-loader phishing campaign dropping Agent Tesla, Remcos, XWorm, and Snake Keylogger, plus TetrisPhantom's GoSerpent RAT hitting SE Asian governments. High urgency.

Aug 15, 2026
Read →
Credential Leaks

Starland RAT + WLDR Implant & Spirals Ransomware: OTX Pulse Analysis — UAT-11795 ClickFix Campaign and Rust-Based Double Extortion Detection Pack

OTX pulses reveal UAT-11795's Starland RAT/WLDR ClickFix campaign targeting US/EU credentials and crypto, plus novel Rust-based Spirals ransomware hitting Asian IT firms. Act now.

Aug 15, 2026
Read →
Credential Leaks

Tomorrowland 2026 Fake Ticket Shop Network: Phishing & Payment Fraud Infrastructure — OTX Pulse Analysis and Detection Pack

~12 fraudulent domains impersonating Tomorrowland 2026 target ticket seekers in EU with phishing, payment fraud & fake biometric checks. Urgent blocking advised.

Aug 14, 2026
Read →
Credential Leaks

Miasma Worm v3 npm Supply-Chain Attack + Tomorrowland Credential-Harvesting Scam Network: OTX Pulse Analysis — Detection Pack

OTX pulses expose Miasma v3 worm delivered via hijacked AsyncAPI npm packages and a 12-domain Tomorrowland phishing ring harvesting credentials and payments across the EU. Hunt now.

Aug 14, 2026
Read →
Credential Leaks

PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Espionage + Linux Botnet Credential Theft — OTX Detection Pack

OTX pulses expose PATCHCORD backdoor hitting Afghan telecom, Evooo1Bot Linux botnet, Miasma v3 npm supply-chain worm & Tomorrowland phishing. Full detection pack.

Aug 14, 2026
Read →
Credential Leaks

Multi-Stage Phishing Relay Chains + Tomorrowland 2026 Festival Fraud: Cloudflare Workers Abuse, HTML Smuggling & Typosquat Campaign — OTX Detection Pack

OTX pulses reveal multi-stage phishing chains abusing Cloudflare Workers/Framer with HTML smuggling, plus a dozen typosquat domains running fake Tomorrowland 2026 ticket scams. Block now.

Aug 13, 2026
Read →
Credential Leaks

Kratos PhaaS, Multi-Stage Redirect Chains & Festival Ticket Fraud: OTX Pulse Analysis — M365 Credential Theft Detection Pack

Kratos PhaaS kit, Cloudflare Workers/Framer redirect chains, and fake Tomorrowland ticket shops are harvesting M365 and payment credentials across US/EU. Urgent: hunt now.

Aug 13, 2026
Read →
Credential Leaks

Armored Likho Still Toolkit (Rust) + Multi-Stage Phishing Relay Chains: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose Armored Likho's Rust-based Still Toolkit targeting Telegram & audio surveillance, plus multi-stage phishing relays abusing Cloudflare Workers. High urgency.

Aug 13, 2026
Read →
Credential Leaks

CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack

OTX pulses expose Midnight Blizzard's hotel Wi-Fi captive portal credential theft (CornFlake/ChocoShell) and UNC6671's multi-brand vishing extortion. Urgent: block IOCs, reset M365 creds.

Aug 12, 2026
Read →
Credential Leaks

Aeternum Blockchain C2, ErrTraffic ClickFix, CaptiveCrunch M365 Phishing, GoldDigger Android: OTX Enterprise Detection Pack

OTX pulses reveal blockchain-C2 infostealers, ClickFix/EtherHiding loaders, hotel captive-portal M365 credential phishing, and GoldDigger Android banking trojan activity. High urgency for identity and endpoint hunting.

Aug 12, 2026
Read →
Credential Leaks

Midnight Blizzard CaptiveCrunch, codemado AiTM Phishing Stack, GhostDesk Spyware & WP-SHELLSTORM Webshell Botnet: OTX Pulse Analysis — Credential Theft Detection Pack

Live OTX pulses expose APT29 hotel Wi-Fi credential theft, a triple-operator AiTM phishing platform, fake CCleaner Chrome spyware, and 1.4M WordPress webshell campaign. Critical urgency.

Aug 12, 2026
Read →
Credential Leaks

Abyssos Modular RAT: LLVM-Obfuscated Credential Theft and VNC Access — OTX Pulse Detection Pack

New Abyssos modular RAT identified with LLVM obfuscation, credential theft, file exfiltration, and VNC access. C2 IPs and SHA256 hashes published. Urgency: HIGH.

Aug 11, 2026
Read →
Credential Leaks

Powercat Infostealer Campaign: Fake Game Cheats Deliver Discord Session Hijacking & Crypto Theft — OTX Pulse Analysis

Powercat infostealer spreads via fake Roblox/Minecraft/GTA V cheats, hijacking Discord sessions and stealing crypto wallets. Multi-stage Java loader. High urgency for enterprise endpoints.

Aug 10, 2026
Read →
Credential Leaks

NUL1DROPPER Slopsquatting Campaign + ChainDrop npm Worm: OTX Pulse Analysis — Supply Chain Credential Theft Detection Pack

OTX pulses reveal two active npm supply chain campaigns — AI-driven slopsquatting dropping Sliver RATs and the self-propagating ChainDrop worm — targeting developer credentials. High urgency.

Aug 10, 2026
Read →
Credential Leaks

SilverFox, Amaranth-Dragon & Lotus Blossom Converge on Indonesian BFSI: ValleyRAT, Amaranth Loader & Havoc C2 Detection Pack

OTX pulse: eight APT clusters targeting Indonesia's BFSI sector with ValleyRAT, Amaranth Loader, LOTUSLITE, Havoc and RustSL. Underground breach data in circulation. High urgency.

Aug 8, 2026
Read →
Credential Leaks

Vanta Stealer: Python-Based Cross-Platform Infostealer Targets Browser Credentials, Discord Tokens & Crypto Wallets — OTX Detection Pack

OTX pulse exposes Vanta Stealer, a PyArmor-obfuscated Python infostealer harvesting Chromium credentials, Discord/Telegram tokens, gaming accounts & crypto wallets. Hunt now.

Aug 7, 2026
Read →
Credential Leaks

Vidar/XMRig Factory-v3, Vanta, MacSync ClickFix, UNC6671 Vishing and Storm-2755 AiTM: OTX Credential-Theft Detection Pack

OTX pulses flag Vidar/XMRig malvertising, Vanta and MacSync stealers, UNC6671 vishing/AiTM and Storm-2755 M365 payroll BEC. Credential theft risk: high.

Aug 7, 2026
Read →
Credential Leaks

Larva-26005 (North Korea) Xctdoor Backdoor Campaign: CRAT Lineage, DLL Side-Loading & Ngrok C2 — OTX Enterprise Detection Pack

DPRK-linked Larva-26005 distributes Xctdoor backdoors via spear-phished LNK files and fake security installers, targeting Korean defense & tech orgs. Hunt and block now.

Aug 6, 2026
Read →
Credential Leaks

keyv & cacheable npm Supply Chain Compromise: Self-Propagating Cloud Credential Theft — OTX Pulse Analysis & Enterprise Detection Pack

Active npm supply chain attack via compromised keyv/cacheable packages deploys self-propagating cloud credential stealers through preinstall hooks. Tens of millions of weekly downloads affected. Immediate action required.

Aug 6, 2026
Read →
Credential Leaks

npm Supply Chain Compromise: keyv & cacheable Packages Poisoned with Ethereum C2 Credential Stealer — OTX Pulse Analysis

Active npm supply chain attack hits keyv/cacheable (tens of millions of weekly downloads). Malicious preinstall hooks steal cloud credentials via Ethereum-contract C2. Hunt now.

Aug 5, 2026
Read →
Credential Leaks

Powercat Java Stealer via Fake Xeno Roblox Cheats + keyv/cacheable npm Supply Chain Compromise: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose two credential-theft campaigns: Powercat Java stealer disguised as Roblox cheats, and a self-propagating npm supply chain worm targeting cloud credentials. High urgency.

Aug 5, 2026
Read →
Credential Leaks

Supply Chain & Blockchain C2: Shai-Hulud, SmartLoader, and EtherRAT Campaigns — OTX Analysis

Active npm supply chain (Shai-Hulud) and blockchain C2 (EtherRAT/SmartLoader) campaigns target devs & finance. Urgent IOCs included.

Aug 5, 2026
Read →
Credential Leaks

ClickFix Campaign: Starland RAT + WLDR Framework Targeting US Financial Sector — OTX Intelligence Briefing

Russian-speaking UAT-11795 deploying trojanized installers for Starland RAT & WLDR framework. US finance sector targeted. CRITICAL urgency.

Aug 4, 2026
Read →
Credential Leaks

Larva-24009 (HeptaX) Phishing: QuasarRAT & UltraVNC via LNK — OTX Pulse Analysis

Active Larva-24009 campaign targets Healthcare with QuasarRAT/UltraVNC via phishing LNKs. High urgency.

Aug 4, 2026
Read →
Credential Leaks

EvilProxy AiTM Campaign: Procurement Lures & Credential Theft — OTX Pulse Analysis

Active AiTM campaign targets education/gov with procurement lures using EvilProxy for MFA bypass and credential theft. High urgency.

Aug 3, 2026
Read →
Credential Leaks

InterlockRAT, Rhysida Ransomware, and Procurement AiTM Phishing: OTX Pulse Analysis

OTX alerts highlight Hive0163 InterlockRAT and Rhysida ransomware operations alongside a global procurement-themed AiTM phishing campaign stealing credentials.

Aug 3, 2026
Read →
Credential Leaks

Gaming Platform Credential Harvesting: Roblox/Minecraft Phishing Ecosystem — OTX Pulse Analysis

Active credential harvesting campaign targeting children via Roblox/Minecraft phishing sites and offerwall schemes.

Aug 2, 2026
Read →
Credential Leaks

Armored Likho's BusySnake Stealer & Gaming Platform Phishing: OTX Pulse Analysis — Enterprise Detection Pack

APT group Armored Likho deploys Python-based BusySnake Stealer against governments and energy sectors, while children's gaming credentials harvested via phishing. High urgency.

Aug 2, 2026
Read →
Credential Leaks

RedLine Stealer C2 Pivot & Toy Ghouls GenieLocker: Maritime Credential Theft & Manufacturing Ransomware

Active RedLine/Formbook credential theft cluster targeting maritime sector; new GenieLocker ransomware from Toy Ghouls hitting manufacturing. High urgency.

Aug 1, 2026
Read →
Credential Leaks

Infostealer Surge: Tax Season Phishing in India & PasasteSinTAG Domain Rotation

Active credential theft campaigns target India & Chile via WhatsApp tax scams and mass domain rotation. Immediate blocking required.

Jul 31, 2026
Read →
Credential Leaks

Phantom Stealer, Ousaban & OctLurk: Global Infostealer & Espionage Operations — OTX Pulse Analysis

OTX alerts to active infostealer campaigns: Phantom Stealer using steganography, Ousaban banking trojan in Iberia, and OctLurk espionage in Central Asia.

Jul 31, 2026
Read →
Credential Leaks

MacSync Stealer, Phantom Infostealer & Global Phishing Surge: OTX Pulse Analysis

Active credential theft campaigns detected: MacSync (macOS), Phantom Stealer (Windows), and mass phishing targeting India and Chile taxpayers.

Jul 31, 2026
Read →
Credential Leaks

ClickFix WebDAV Execution & PasasteSinTAG Phishing Surge: OTX Pulse Analysis — Credential Theft Infrastructure

OTX Alert: Active ClickFix WebDAV attacks and massive PasasteSinTAG phishing wave targeting Chile. Block domains now.

Jul 30, 2026
Read →
Credential Leaks

Shai-Hulud NPM Worm & ClickFix WebDAV: OTX Pulse Analysis — Enterprise Detection Pack

Active NPM supply chain attacks and ClickFix campaigns targeting GitHub/AWS credentials. Urgent detection engineering required.

Jul 30, 2026
Read →
Credential Leaks

Multi-Vector Credential Theft: Malicious VPN Extensions, NPM Worms, and Phishing Infrastructure — OTX Pulse Analysis

Credential theft surge via malicious VPN browser updates, NPM supply chain worms, and Chilean phishing. Urgent hunt required.

Jul 30, 2026
Read →
Credential Leaks

RMM Exploitation & Supply Chain Worms: TaskWeaver, Djinn Stealer, and npm Attacks

Active credential theft targeting devs via npm worms, SimpleHelp RMM exploits (CVE-2026-48558), and evolving ClickFix. High urgency.

Jul 29, 2026
Read →
Credential Leaks

Bumblebee, npm Supply Chain, and ClickFix: OTX Pulse Analysis — Credential Theft & Akira Ransomware

Active campaigns via SEO poisoning, npm worms, and ClickFix targeting admins/developers for credential theft and Akira ransomware.

Jul 29, 2026
Read →
Credential Leaks

Flying Eagle RAT, Shai-Hulud NPM Worm & ClickFix: Cross-Vector Credential Theft Campaigns — Detection Pack

Active infostealer campaigns targeting finance & dev environments via Android RAT, supply chain attacks, and WebDAV social engineering.

Jul 29, 2026
Read →
Credential Leaks

NagaPocker Mobile Credential Theft Campaign: QR Code Phishing Attacks Targeting Ukraine

Active mobile credential theft campaign using QR code phishing targeting Ukrainian financial sector with 11K+ daily detections.

Jul 28, 2026
Read →
Credential Leaks

AI Agent LLMjacking & QR Code Phishing: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal active exploitation of AI Model Context Protocol for credential theft and QR code phishing campaigns targeting financial sectors.

Jul 28, 2026
Read →
Credential Leaks

CastleLoader, NeedleStealer & AI MCP Exploits: Multi-Vector Credential Theft — OTX Pulse Analysis

Active campaigns deploying CastleLoader/NeedleStealer and exploiting AI infrastructure alongside QR-based mobile phishing for credential harvesting.

Jul 28, 2026
Read →
Credential Leaks

Fake Corepack Supply Chain Attack: OpenShield & Apprunner Distribution

Fake Corepack site targeting developers with OpenShield infostealer and Apprunner proxyware via typosquatting. Urgent blocking required.

Jul 27, 2026
Read →
Credential Leaks

Langflow AI Pipeline Exploitation (CVE-2026-55255): Chained RCE & IDOR Credential Theft

Active exploitation of Langflow via chained RCE and IDOR vulnerabilities results in credential theft and botnet deployment.

Jul 26, 2026
Read →
Credential Leaks

Kimsuky's KimJongRAT & Langflow Exploitation: OTX Pulse Analysis — Enterprise Detection Pack

Kimsuky abuses GitHub for KimJongRAT attacks; Langflow CVEs facilitate credential theft. High urgency.

Jul 26, 2026
Read →
Credential Leaks

Supply Chain Compromise: Klue to LastPass OAuth Token Theft — CRM Data Breach

LastPass CRM data exposed via Klue vendor compromise using stolen OAuth tokens. Urgency: High.

Jul 26, 2026
Read →
Credential Leaks

GitHub Actions Abuse & Supply Chain OAuth Theft: cPanel Exploit & CRM Data Breach

OTX Alert: GitHub Actions abuse powers cPanel exploitation while supply chain OAuth theft exposes LastPass CRM data.

Jul 25, 2026
Read →
Credential Leaks

Cisco SD-WAN Zero-Day & GitHub Actions Abuse: Supply Chain Credential Theft

Critical OTX pulses reveal CVE-2026-20245 and GitHub Actions abuse targeting enterprise credentials, OAuth tokens, and CRM data.

Jul 25, 2026
Read →
Credential Leaks

Prinz Eugen Ransomware & GitHub Actions Abuse: OTX Pulse Analysis — Enterprise Detection Pack

ROOTBOY deploys Prinz Eugen ransomware; massive GitHub Actions supply chain attack targeting cPanel; LastPass supply chain breach.

Jul 25, 2026
Read →

Showing 50 of 326 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every Credential LeaksReport Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.