Dark Side Intelligence Category

Credential Leaks Intelligence

Infostealer malware campaigns (Lumma, RedLine, Vidar, StealC), combo list releases on dark web forums, credential stuffing operations, and enterprise exposure reports.

396 reports available•Refreshed every 5 minutes

Credential Leaks — Archive & Latest

50 reports loaded
Credential Leaks

DARKLANTERN, SPEAKINGSTONE & ENDLESSDOORS: ZBT Router Firmware Implants in the Global Supply Chain — OTX Pulse Analysis & Detection Pack

Three firmware implants embedded in ZBT routers expose root shell access via unauthenticated UDP 9992 backdoor. Global supply chain reach across 11 countries. Critical urgency.

Sep 26, 2026
Read →
Credential Leaks

AnonyMousKIT AI-Powered PhaaS Supply Chain: 506-Domain Apple Activation Lock Phishing Network — OTX Detection Pack

OTX exposes AnonyMousKIT, an AI-driven PhaaS with 506 domains harvesting Apple ID credentials via SMS, WhatsApp, email & vishing. Gov/Edu targeted. HIGH urgency.

Sep 26, 2026
Read →
Credential Leaks

Dark Caracal GoCaracal Framework + Russian Evilginx OAuth Phishing Clusters: OTX Pulse Analysis — Credential Theft Detection Pack

OTX pulses reveal Dark Caracal's new GoCaracal modular espionage framework targeting Latin America and Russian clusters (UNC6293/UNC7005/UNC5976) running Evilginx OAuth/device-code phishing against academia and government. High urgency — credential theft at scale.

Sep 25, 2026
Read →
Credential Leaks

RemotePanel + BoundSiphon: ClickFix-Delivered Dual-Payload Toolkit for Persistent Access & Browser Credential Theft — OTX Detection Pack

OTX pulse details two undocumented .NET payloads — RemotePanel HVNC RAT and BoundSiphon browser stealer — deployed via ClickFix chains with blockchain-based C2 resolution. Immediate credential rotation advised.

Sep 25, 2026
Read →
Credential Leaks

MacSync macOS Stealer + HookBot/ERMAC Android Banking Leak: OTX Pulse Analysis — Credential-Theft Detection Pack

OTX flags MacSync targeting macOS crypto users/devs and HookBot/ERMAC source leak enabling Android banking panel sprawl. Hunt now; credential exposure likely.

Sep 24, 2026
Read →
Credential Leaks

CARBONATO Docker Botnet + PavinLoader/Amatera Stealer: OTX Pulse Analysis — Exposed Daemon Exploitation & ClickFix Credential Theft Detection Pack

OTX pulses reveal CARBONATO botnet abusing exposed Docker daemons and PavinLoader delivering Amatera Stealer via ClickFix. Credential theft focus. High urgency.

Sep 24, 2026
Read →
Credential Leaks

SectopRAT via Fake Claude Desktop Installers: Bing Malvertising, EtherHiding C2 & DLL Sideloading — OTX Detection Pack

FakeAgent campaign pushes trojanized Claude Desktop installers via Bing malvertising, delivering SectopRAT through DLL sideloading, EtherHiding blockchain C2, and scheduled task persistence.

Sep 23, 2026
Read →
Credential Leaks

ClickFix AS202412 Infostealer Chains + Red Heron WordPress Raids: OTX Detection Pack for DarkGate, Amadey, Matanbuchus

OTX pulses: ClickFix fake-CAPTCHA chains on AS202412 and Red Heron WordPress/gov record theft; credential exposure high-block IOCs, hunt now.

Sep 23, 2026
Read →
Credential Leaks

DarkMe RAT, RemControl Banking Trojan & ClickFix Loader Chains: OTX Pulse Analysis — Credential Theft Detection Pack

OTX pulses reveal credential theft surge: Water Hydra's DarkMe RAT, RemControl Android banking trojan, ClickFix loader chains, and Red Heron WordPress exploitation. Act now.

Sep 23, 2026
Read →
Credential Leaks

Vidar Stealer VM-Based String Obfuscation & Custom ChaCha20-Style Ciphers: OTX Pulse Analysis — Enterprise Detection Pack

Vidar infostealer deploys bytecode VM and custom ARX stream ciphers to defeat string analysis. Credential theft at scale — hunt now, rotate exposed identities within 24h.

Sep 22, 2026
Read →
Credential Leaks

Typosquatted AI Platform Malware Distribution: 'claude.ai.download-app.us' Credential-Harvesting Campaign — OTX Detection Pack

OTX pulse confirms adversaries abusing trusted AI platform branding (claude.ai typosquats) to distribute credential-harvesting malware across 8 critical sectors. Hunt now.

Sep 22, 2026
Read →
Credential Leaks

Mirage2FA PhaaS Kit: Microsoft 365 Session Hijacking via AiTM — OTX Pulse Analysis & Detection Pack

Mirage2FA phishing-as-a-service kit hijacks Microsoft 365 sessions via AiTM attacks, 4K+ US victims. Blocking, hunting, and identity response guidance inside.

Sep 19, 2026
Read →
Credential Leaks

Mirage2FA AiTM PhaaS + T-Mobile Smishing Credential Campaigns: OTX Pulse Analysis — Session Hijack Detection Pack

OTX pulses flag Mirage2FA AiTM phishing-as-a-service hijacking M365 sessions (4K+ US victims) and a T-Mobile rewards smishing wave. Credential/session theft — hunt now.

Sep 19, 2026
Read →
Credential Leaks

Mirage2FA PhaaS, Offside Wallet Theft Factory & T-Mobile Smishing: OTX Pulse Analysis — Credential Theft Detection Pack

Three active credential-theft campaigns: Mirage2FA AiTM phishing hijacking M365 sessions (4K+ US victims), 77 malicious Firefox extensions stealing crypto wallets, and T-Mobile smishing.

Sep 18, 2026
Read →
Credential Leaks

Mirage2FA AiTM, Spyroid PhaaS, and DXSCAN Go C2: OTX Credential-Theft Detection Pack for M365, Banking, and Edge Exploits

Live OTX pulses show converging credential-theft campaigns: Mirage2FA AiTM M365 session theft, Spyroid PhaaS banking fraud, T-Mobile smishing, DXSCAN mass harvesting. Hunt now.

Sep 18, 2026
Read →
Credential Leaks

PolinRider Supply-Chain Infostealer, Clop LEMURLOOT Implant & Settra Ransomware: OTX Pulse Analysis — Credential Theft Detection Pack

OTX pulses reveal PolinRider supply-chain infostealer, Clop Windchill extortion implant, Settra ransomware via MeshAgent RMM, and a 16K-credential harvest. High urgency.

Sep 18, 2026
Read →
Credential Leaks

Operation RapidRust (APT36) + Mirage2FA AiTM Phishing Kit: Rust-Based Backdoors and M365 Session Theft — OTX Detection Pack

OTX pulses flag APT36's Operation RapidRust hitting India/Afghanistan gov & defense, and Mirage2FA AiTM phishing hijacking 4K+ M365 sessions. Urgent: hunt & block.

Sep 17, 2026
Read →
Credential Leaks

Octagon Android Banking Bot + Mirage2FA Session Hijacking + APT36 Operation RapidRust: OTX Pulse Analysis — Enterprise Credential Theft Detection Pack

OTX pulses reveal Octagon Android MaaS targeting crypto/banking apps, Mirage2FA AiTM phishing hijacking 4K+ Microsoft 365 sessions, and APT36's RapidRust toolkit hitting government targets. HIGH urgency.

Sep 17, 2026
Read →
Credential Leaks

VectraRAT MaaS Platform + APT36 Operation RapidRust: OTX Pulse Analysis — Infostealer & Espionage Detection Pack

OTX pulses expose VectraRAT MaaS (Amadey/Vidar delivery) and APT36's Rust-based RapidRust arsenal targeting finance, government, and defense. High urgency.

Sep 17, 2026
Read →
Credential Leaks

NightEagle APT GhostContainer Exchange Backdoor + AMOS macOS Stealer ClickFix Campaign: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses expose NightEagle (APT-Q-95) deploying GhostContainer on Russian Exchange servers and AMOS macOS stealer spreading via ClickFix — credential theft at scale. Act now.

Sep 16, 2026
Read →
Credential Leaks

CVE-2024-21762 FortiGate SSL-VPN Exploitation + MeshCentral RMM Persistence: Thai Telecom Intrusion — OTX Detection Pack

OTX pulse reveals active intrusion against Thai ISP 3BB via FortiGate CVE-2024-21762 exploit and MeshCentral RMM for covert C2. High urgency for edge device owners.

Sep 15, 2026
Read →
Credential Leaks

KATARU IoT Botnet + Mirai-Style DDoS: OTX Pulse Analysis — Telnet Brute-Force, Public Linux LPE Exploits, and Encrypted C2 Detection Pack

OTX flags KATARU IoT malware using Telnet brute-force, Mirai-style DDoS and public Linux LPE CVEs; hunt edge devices, cron persistence and C2 now.

Sep 14, 2026
Read →
Credential Leaks

PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Backdoors and Multi-Functional Linux Botnet — OTX Pulse Detection Pack

Two active campaigns: Operation C-Major's PATCHCORD/SHEETCORD cluster hitting Afghan telecom & South Asian critical infrastructure via Google Sheets C2, plus Evooo1Bot Linux botnet. High urgency.

Sep 12, 2026
Read →
Credential Leaks

Armored Likho 'Still Toolkit' Rust Espionage + Storm-3121 Passkey AiTM Phishing: OTX Pulse Analysis — Credential Theft Detection Pack

Armored Likho's Rust Still Toolkit spies on Russian gov/tech/edu orgs while Storm-3121 passkey AiTM phishing hijacks cloud identities. High urgency.

Sep 12, 2026
Read →
Credential Leaks

Storm-3121/Storm-3032 Passkey AiTM Phishing + AI-Driven PaperCut Exploitation: OTX Pulse Analysis — Identity & Credential Defense Pack

OTX pulses reveal Storm-3121/Storm-3032 passkey-themed AiTM phishing compromising cloud identities, plus AI-automated PaperCut exploitation (CVE-2026-81578/82078). Credential theft risk: HIGH.

Sep 11, 2026
Read →
Credential Leaks

Midnight Blizzard CaptiveCrunch, LegionLoader ClickFix & Passkey AiTM Campaigns: OTX Pulse Analysis — Identity Theft Detection Pack

OTX pulses expose UNC2452 hotel captive-portal M365 theft, ClickFix LegionLoader drops, passkey AiTM phishing, and LATAM banking trojans. Credential-focused orgs must act now.

Sep 11, 2026
Read →
Credential Leaks

njRAT/DCRAT, GhostDesk Chrome Spyware, PaperCut CVEs & Storm-3121 Passkey AiTM: OTX Credential-Theft Detection Pack

OTX pulses show SEO-poisoned GTA6 ISOs, fake CCleaner GhostDesk spyware, PaperCut exploitation and passkey AiTM driving credential/cloud theft. Hunt now.

Sep 10, 2026
Read →
Credential Leaks

UTA0560/JungleBamboo 0-day Chain, Djinn Stealer, Gigabud/Vwork & PaperCut AI Exploitation: OTX Enterprise Detection Pack

OTX pulses show converging credential-theft ops: Chrome/Windows 0-days, Djinn/TaskWeaver, GTA6 lure RATs, Gigabud/Vwork, and AI-scaled PaperCut exploitation. Act now.

Sep 10, 2026
Read →
Credential Leaks

Aeternum Blockchain C2 Botnet: XWorm, ZingoStealer and XMRig Loader Activity — OTX Detection Pack

OTX pulse flags LenAI-linked Aeternum loader using Polygon smart contracts as resilient C2, staging XWorm, ZingoStealer and XMRig. Hunt RPC endpoints, DNS and loader hashes now.

Sep 9, 2026
Read →
Credential Leaks

APT37 'Ted' Backdoor Linux Toolkit + Abyssos RAT: OTX Pulse Analysis — Infostealer Detection Pack

APT37 deploys trojanized HAProxy backdoor against South Korean media/auto; new Abyssos RAT steals credentials via VNC. Urgent hunt guidance inside.

Sep 9, 2026
Read →
Credential Leaks

Vidar VM-Obfuscated Stealer + ClearFake/Amatera WebDAV Chain (UAT-10820): OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal VM-obfuscated Vidar infostealer and UAT-10820's ClearFake/Amatera WebDAV chain hitting government targets in 7 countries. Credential theft at scale — hunt now.

Sep 9, 2026
Read →
Credential Leaks

BigBear 2.0 Evilginx2 PhaaS Campaign: AiTM Microsoft 365 Credential Theft — OTX Detection Pack

BigBear 2.0, an Evilginx2-based phishing-as-a-service run by 'General Boss', is stealing M365 credentials via AiTM across 42 Vultr VPS nodes. High urgency.

Sep 8, 2026
Read →
Credential Leaks

PEEP Browser RAT 'Smart Bookmarks' Chrome/Edge Backdoor: OTX Pulse Analysis — Enterprise Detection Pack

PEEP Chrome RAT poses as Smart Bookmarks, hijacks browser sessions and enables host command execution after admin compromise; hunt and block now.

Sep 7, 2026
Read →
Credential Leaks

UNC6671 Multi-Brand Vishing Extortion: Okta-Themed AiTM Phishing Infrastructure — OTX Pulse Detection Pack

UNC6671 vishing crews pose as IT helpdesk to push Okta/passkey spoof portals, bypassing MFA via AiTM. Financial services & enterprise cloud targets. Hunt now.

Sep 6, 2026
Read →
Credential Leaks

MacSync Stealer + ClickFix Fake CAPTCHA Campaign: OTX Pulse Analysis — macOS Credential & Crypto Wallet Detection Pack

MacSync infostealer targeting macOS via ClickFix fake-CAPTCHA social engineering. Harvests browser credentials and crypto wallets. C2 infrastructure live. Hunt now.

Sep 5, 2026
Read →
Credential Leaks

SmartLoader NodeJS Infostealer + SecFlow AI-Orchestrated Intrusions: OTX Pulse Analysis — Enterprise Detection Pack

Fake AI GitHub repos deploy SmartLoader/NodeJS infostealer via blockchain C2; Chinese operator uses SecFlow AI agents against Asian gov/edu networks. HIGH urgency.

Sep 4, 2026
Read →
Credential Leaks

The Gentlemen Ransomware Group — TukTuk C2 v2.0 Framework & EDRKiller BYOVD Toolkit: OTX Pulse Analysis + Enterprise Detection Pack

OTX pulse exposes The Gentlemen's TukTuk C2 v2.0 framework with cross-platform agents and EDR-neutralization toolkit targeting US defense, healthcare, and aerospace. Hunt and block now.

Sep 3, 2026
Read →
Credential Leaks

Woodgnat Node.js Abuse Campaign: ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix — OTX Detection Pack

Woodgnat actor abuses signed node.exe to run ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix lures. 180 IOCs, EtherHiding C2. Immediate hunt required.

Sep 3, 2026
Read →
Credential Leaks

Tampered Exodus Wallet Installer Drops Modular RAT: Dll4 Suite Credential Theft Campaign — OTX Detection Pack

Fake Exodus crypto wallet installers are deploying a six-module RAT (Dll4_*) via JavaScript droppers and Azure Table Storage C2. High urgency — hunt now.

Sep 3, 2026
Read →
Credential Leaks

Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack

OTX pulses detail M365 AiTM session-token phishing and a fake Exodus wallet modular RAT using Azure-backed C2. Enterprise identity and crypto-adjacent users face elevated credential-theft risk.

Sep 2, 2026
Read →
Credential Leaks

Zer0day Stealer, StreamRat, Knight Office AiTM + Exodus RAT: OTX Credential-Theft Detection Pack

OTX flags AiTM M365 token theft, Android banking takeover, Rust infostealer/RAT pipeline and trojanized Exodus RAT; reset credentials now.

Sep 2, 2026
Read →
Credential Leaks

Sality Botnet Sinkhole & Tampered Exodus Wallet Modular RAT: OTX Pulse Analysis — Infostealer & Credential Theft Detection Pack

OTX pulses reveal the Sality P2P botnet takedown (EggJagger clipper delivery) and a modular RAT hidden in fake Exodus wallet installers. Credential and crypto theft at scale. Urgent.

Sep 2, 2026
Read →
Credential Leaks

Packagist Supply-Chain iOS Spyware Chain (CVE-2025-31277 / CVE-2025-43529): FunNULL-Linked Crypto Seed Theft — OTX Pulse Analysis

13 malicious Packagist Composer themes inject JS delivering iOS WebKit-to-kernel spyware that steals crypto wallet seeds. FunNULL infrastructure implicated. URGENT.

Sep 1, 2026
Read →
Credential Leaks

BraZetsu IAB Framework & Packagist iOS Spyware Chain: OTX Pulse Analysis — Exilware Initial Access + Supply Chain Credential Theft Detection Pack

OTX pulses expose Exilware's BraZetsu Python IAB framework targeting LATAM/Iberian finance, plus 13 malicious Packagist themes weaponizing iOS WebKit CVEs for crypto seed theft. Urgent hunt advised.

Sep 1, 2026
Read →
Credential Leaks

JSCeal V8 Bytecode Cryptocurrency Stealer: Compiled Node.js Infostealer Evading Static Analysis — OTX Pulse Detection Pack

OTX pulse exposes JSCeal, a cryptocurrency-focused infostealer shipped as compiled V8 bytecode with RC4 string encryption, control-flow flattening, and MITM browser theft. High urgency for SOC hunting.

Aug 31, 2026
Read →
Credential Leaks

Blind Eagle (APT-C-36) GitHub Loader Pipeline: AsyncRAT, DcRat, Remcos & XWorm Targeting Colombian Government — OTX Detection Pack

OTX pulse exposes Blind Eagle operator staging AsyncRAT, DcRat, Remcos & XWorm via GitHub loaders against Colombian government. IOCs + Sigma/KQL detections inside.

Aug 31, 2026
Read →
Credential Leaks

AnonyMousKIT AI-Powered PhaaS Supply Chain: OTX Pulse Analysis — Apple Activation Lock Credential Harvesting Detection Pack

AnonyMousKIT PhaaS platform uses AI vishing and multi-channel phishing across 506 domains to steal Apple credentials and disable Activation Lock. High urgency for government and education sectors.

Aug 29, 2026
Read →
Credential Leaks

DARKLANTERN/SPEAKINGSTONE Implants, Evilginx AiTM & AnonyMousKIT PhaaS: OTX Credential-Theft Detection Pack

OTX pulses expose converging credential theft: malicious browser extensions, ZBT firmware implants, AI PhaaS and Evilginx AiTM. Block IOCs, reset exposed sessions, harden edge now.

Aug 29, 2026
Read →
Credential Leaks

Dysphoria Blockchain-C2 Botnet, Browser-Extension Wallet Drainers & AnonyMousKIT PhaaS: OTX Credential-Theft Campaign Analysis — Enterprise Detection Pack

OTX exposes converging credential-theft ops: Dysphoria botnet, 19 wallet-draining browser extensions, ZBT implants, and AnonyMousKIT PhaaS. Hunt immediately.

Aug 29, 2026
Read →
Credential Leaks

pepesoft.exe Infostealer + ZBT Firmware Implants + XenoRAT Spear-Phishing: OTX Pulse Analysis — Enterprise Detection Pack

OTX pulses reveal NuGet supply-chain infostealers, ZBT router firmware backdoors, Kimsuky XenoRAT campaigns, and browser wallet drainers. Immediate IOC blocking and credential rotation required.

Aug 28, 2026
Read →

Showing 50 of 396 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every Credential Leaks Report Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.