Credential Leaks Intelligence
Infostealer malware campaigns (Lumma, RedLine, Vidar, StealC), combo list releases on dark web forums, credential stuffing operations, and enterprise exposure reports.
Credential Leaks — Archive & Latest
AI Agent LLMjacking & QR Code Phishing: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal active exploitation of AI Model Context Protocol for credential theft and QR code phishing campaigns targeting financial sectors.
CastleLoader, NeedleStealer & AI MCP Exploits: Multi-Vector Credential Theft — OTX Pulse Analysis
Active campaigns deploying CastleLoader/NeedleStealer and exploiting AI infrastructure alongside QR-based mobile phishing for credential harvesting.
Fake Corepack Supply Chain Attack: OpenShield & Apprunner Distribution
Fake Corepack site targeting developers with OpenShield infostealer and Apprunner proxyware via typosquatting. Urgent blocking required.
Langflow AI Pipeline Exploitation (CVE-2026-55255): Chained RCE & IDOR Credential Theft
Active exploitation of Langflow via chained RCE and IDOR vulnerabilities results in credential theft and botnet deployment.
Kimsuky's KimJongRAT & Langflow Exploitation: OTX Pulse Analysis — Enterprise Detection Pack
Kimsuky abuses GitHub for KimJongRAT attacks; Langflow CVEs facilitate credential theft. High urgency.
Supply Chain Compromise: Klue to LastPass OAuth Token Theft — CRM Data Breach
LastPass CRM data exposed via Klue vendor compromise using stolen OAuth tokens. Urgency: High.
GitHub Actions Abuse & Supply Chain OAuth Theft: cPanel Exploit & CRM Data Breach
OTX Alert: GitHub Actions abuse powers cPanel exploitation while supply chain OAuth theft exposes LastPass CRM data.
Cisco SD-WAN Zero-Day & GitHub Actions Abuse: Supply Chain Credential Theft
Critical OTX pulses reveal CVE-2026-20245 and GitHub Actions abuse targeting enterprise credentials, OAuth tokens, and CRM data.
Prinz Eugen Ransomware & GitHub Actions Abuse: OTX Pulse Analysis — Enterprise Detection Pack
ROOTBOY deploys Prinz Eugen ransomware; massive GitHub Actions supply chain attack targeting cPanel; LastPass supply chain breach.
LokiBot Resurgence & GitHub Actions Supply Chain Attacks: OTX Pulse Analysis
OTX detects active LokiBot credential theft, GitHub Actions abuse for cPanel exploitation, and supply chain OAuth token theft.
Hades Implant, AMOS Stealer, and CI/CD Abuse: OTX Pulse Analysis — Credential Theft Campaign
Active campaigns utilizing Hermes AI, AMOS infostealer, and GitHub Actions to harvest credentials via supply chain and cloud exploits.
Mistic Backdoor, Autonomous AI Agents, and GitHub Actions Abuse: OTX Pulse Analysis — Enterprise Detection Pack
Active campaigns deploying Mistic backdoor and AI-driven Hades implant. High urgency: credential theft and supply chain exploits detected.
CyberStrike Harvester & TAG-195 MaaS: Credential Harvesting & AI Supply Chain Attacks — OTX Pulse Analysis
Critical credential theft via FortiBleed and TAG-195 MaaS targets gov/finance. Immediate IOC blocking required.
SectopRAT & StealC: Claude AI Malvertising and Supply Chain CRM Theft
Active malvertising pushes SectopRAT via Claude AI lures; Supply chain breach exposes LastPass CRM data.
NadMesh Botnet Targeting AI Infrastructure: OTX Pulse Analysis — Credential Theft Detection Pack
NadMesh Go-botnet targets AI infra (ComfyUI/Ollama) via Redis exploits to steal credentials. Critical urgency.
Dolphin X & Phantom Stealer v3.5: AI-Driven & Multi-Stage Infostealer Campaigns — Enterprise Detection Pack
Dolphin X targets 300+ apps with AI profiling; Phantom Stealer v3.5 phishing Finance/Gov via multi-stage JS payloads. High urgency.
Icarus Supply Chain Attack via Klue: OAuth Abuse & Salesforce CRM Data Exfiltration — OTX Pulse Analysis
Icarus group exploits Klue supply chain to hijack OAuth tokens, targeting Salesforce/Gong for CRM data theft. Urgent audit required.
EvilProxy AiTM Phishing Campaign: Global Procurement Lures & Session Hijacking — OTX Pulse Analysis
Active AiTM campaign targeting Education/Gov using procurement lures to bypass MFA via EvilProxy. High urgency.
Operation STANDOFF: Multi-Vector Infostealer Campaign Leveraging GitHub Redirects
Active Russian-speaking campaign uses TimeWeb C2 and GitHub redirects to distribute Raccoon, RedLine, Glupteba. Urgency: High.
JADEPUFFER ENCFORGE Ransomware & Kimsuky BirdTroy/DriveTroy: OTX Pulse Analysis
Alert: JADEPUFFER targets AI infra with ENCFORGE ransomware; Kimsuky deploys BirdTroy/DriveTroy stealers via supply chain. High urgency.
Blind Eagle AsyncRAT Campaigns & Entra Passkey Vishing: OTX Pulse Analysis
APT-C-36 evolves toolkit with AutoIt/RunPE; O-UNC-066 vishes for M365 passkeys. High urgency credential theft.
Operation FortiBleed: Fortinet SSL VPN Credential Harvesting & GPU Cracking Infrastructure
Critical threat: Large-scale FortiBleed campaign targeting Fortinet SSL VPNs via brute force and GPU hash cracking. Immediate action required.
Operation Poisson: Havoc C2 & Python Keylogger Targeting French Automotive Sector — OTX Pulse Analysis
French-speaking threat actor 'Poisson' targets automotive sector with Havoc C2 and Python keylogger in credential theft campaign. URGENCY: HIGH
Kratos PhaaS Microsoft 365 Credential Theft: OTX Pulse Analysis — Enterprise Detection Pack
Kratos PhaaS targets Microsoft 365 in US/EU. Detect credential theft, account takeover risks, and infrastructure with this intel brief.
NadMesh Cloud Botnet, Kratos PhaaS & Remcos RAT: OTX Pulse Analysis — Enterprise Credential Theft Surge
OTX Pulse Alert: Surge in credential theft via NadMesh cloud botnet, Kratos PhaaS, Remcos RAT, and OkoBot targeting M365 and Crypto wallets. High Urgency.
ClickFix & OkoBot Campaigns: Multi-Vector Infostealer Wave Targeting Finance and Crypto Sectors — Detection Engineering Brief
Active ClickFix & GST-themed phishing campaigns delivering SmartRAT, Remcos, and OkoBot infostealers targeting Brazil, India. Immediate blocking required.
ACR Stealer, OkoBot & Kratos PhaaS: OTX Pulse Analysis — Multi-Vector Credential Theft & RAT Campaigns
Active campaigns deploying ACR Stealer, OkoBot, and Kratos PhaaS targeting enterprises and M365 accounts. High urgency credential theft.
UAT-11795 Starland RAT, Spirals Ransomware, and the Global Lua Loader Threat — OTX Intelligence Briefing
OTX Pulse Analysis: UAT-11795 deploys Starland RAT alongside Spirals ransomware and global infostealer campaigns.
CylindricalCanine RAT, OkoBot Framework, and Kratos PhaaS: OTX Pulse Analysis — Enterprise Credential Theft Defense
Active campaigns deploying Golden Gh0st RAT, OkoBot crypto-stealers, and Kratos PhaaS targeting M365 and finance.
ClickFix Surge: Potemkin, TELEPUZ, and OkoBot Credential Theft Campaigns — OTX Pulse Analysis
Surge in ClickFix attacks delivering Potemkin, TELEPUZ, and OkoBot infostealers. Active credential harvesting across retail and finance sectors.
OkoBot, MacSync Stealer & UNC6508: Multi-Vector Credential Harvesting Campaigns — Enterprise Detection Pack
Active credential harvesting campaigns targeting crypto users, healthcare research, and AI platforms via sophisticated infection chains.
OkoBot, LummaC2 & O-UNC-038: Credential Harvesting & Infostealer Surge — OTX Analysis
Surge in credential theft via OkoBot framework, LummaC2 infostealers, and O-UNC-038 HR phishing. Critical for SOC teams to block IOCs immediately.
Jalisco Toolkit, Miasma v3 & TuxBot Botnet: OTX Pulse Analysis — Enterprise Detection Pack
OTX Pulse Analysis: Active PhaaS, npm supply chain attacks, and LLM-generated IoT botnets targeting credentials and infrastructure.
Miasma Infostealer & AsyncAPI Supply Chain Compromise: GitHub Actions 'Pwn Request' Analysis
Urgent: Threat actors exploited GitHub Actions to publish malicious npm packages (Miasma), stealing CI/CD credentials via 'pwn request'.
Tomorrowland 2026 Credential Harvesting Campaign: OTX Pulse Analysis — Phishing Infrastructure
Active credential harvesting campaign targeting Tomorrowland 2026 attendees via fake ticket shops. High urgency for financial fraud.
jscrambler npm Supply Chain Compromise: Native Binary Infostealer Injection
Critical npm supply chain attack on jscrambler v8.14.0 drops hidden binaries via preinstall hook. Immediate credential theft hunt required.
UNC6240 (ShinyHunters): CVE-2026-35273 Oracle PeopleSoft Zero-Day Exploitation with MeshCentral C2 Infrastructure
UNC6240 exploits Oracle PeopleSoft zero-day in education sector using MeshCentral C2. 100+ orgs affected. CRITICAL urgency.
Supply Chain Attack: Malicious Injective SDK npm Package v1.20.21 Exfiltrating Web3 Wallet Keys
Compromised npm package @injectivelabs/sdk-ts v1.20.21 exfiltrates private keys via supply chain attack. High urgency for blockchain devs.
ValleyRAT & Injective SDK Supply Chain: OTX Pulse Analysis — Credential Theft Campaign
Active credential theft campaigns targeting Indonesian BFSI and crypto developers via ValleyRAT and compromised npm packages.
SilabRAT, Injective SDK Supply Chain Attack, and Albiriox Android Trojan: OTX Pulse Analysis — Enterprise Detection Pack
OTX detects SilabRAT MaaS, npm supply chain attack, and Albiriox Android trojan targeting crypto & finance. Urgent detection needed.
Multi-Ecosystem Supply Chain Attack: npm & PyPI Typosquatting Campaign Targeting Payment SDKs
Active typosquatting campaign on npm/PyPI steals dev credentials via fake payment SDKs. High urgency.
Meta Business Manager Phishing & PyPI/NPM Supply Chain Attack — OTX Pulse Analysis
Active credential theft via npm/PyPI typosquatting and Meta Business phishing. Urgent IOC review required.
Vidar Stealer, Supply Chain Typosquatting & Meta Phishing: OTX Pulse Analysis
OTX detects active Vidar Infostealer campaigns, npm/PyPI typosquatting, and Meta Business Manager abuse targeting credentials.
GIFTEDCROOK, OtterCookie & BRICKSTORM: OTX Pulse Analysis — Multi-Vector Credential Theft Campaigns
Active campaigns by SHADOW-EARTH-066 and UNK_DeadDrop exploit WinRAR and GitHub to steal credentials. Urgent detection required.
CrySome RAT, Salat Stealer & UNK_MassTraction: Multi-Vector Credential Theft Operations — OTX Intel
Active campaigns deploy CrySome RAT and Salat Stealer for credential theft, while UNK_MassTraction exploits university mail servers. Immediate action required.
Gaming Platform Phishing & Credential Harvesting: Roblox/Minecraft Targeted Campaign Analysis
Active phishing campaign targeting children via fake Roblox/Minecraft sites. High urgency for Education sectors to block IOCs.
Pink Vishing & Global PhaaS Campaigns: OTX Credential Theft Analysis
Pink actor vishing, global smishing operations, and gaming credential theft target finance, telco, and education sectors.
Argamal RAT & Smishing-as-a-Service: Multi-Vector Credential Theft Campaigns — OTX Pulse Analysis
RAT via game mods & smishing ops targeting credentials across gaming, telecom, finance. High urgency: immediate blocking required.
BoryptGrab Stealer & Gafgyt C0XMO Botnet: OTX Pulse Analysis
Active campaigns deploying BoryptGrab stealer via GitHub impersonation and Gafgyt C0XMO botnet via router exploits. Credential theft focus.
SessionGate & BoryptGrab: TDS-Driven Infostealer Ecosystem OTX Analysis
Active campaigns using Traffic Distribution Systems (TDS) and GitHub impersonation to deploy SessionGate, RemusStealer, and BoryptGrab. Urgency: High.
Showing 50 of 285 reports. Archive expands automatically as new intel is generated.
Every Credential LeaksReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.