Credential Leaks Intelligence
Infostealer malware campaigns (Lumma, RedLine, Vidar, StealC), combo list releases on dark web forums, credential stuffing operations, and enterprise exposure reports.
Credential Leaks — Archive & Latest
UNC6671 Multi-Brand Vishing Extortion: Okta-Themed AiTM Phishing Infrastructure — OTX Pulse Detection Pack
UNC6671 vishing crews pose as IT helpdesk to push Okta/passkey spoof portals, bypassing MFA via AiTM. Financial services & enterprise cloud targets. Hunt now.
MacSync Stealer + ClickFix Fake CAPTCHA Campaign: OTX Pulse Analysis — macOS Credential & Crypto Wallet Detection Pack
MacSync infostealer targeting macOS via ClickFix fake-CAPTCHA social engineering. Harvests browser credentials and crypto wallets. C2 infrastructure live. Hunt now.
SmartLoader NodeJS Infostealer + SecFlow AI-Orchestrated Intrusions: OTX Pulse Analysis — Enterprise Detection Pack
Fake AI GitHub repos deploy SmartLoader/NodeJS infostealer via blockchain C2; Chinese operator uses SecFlow AI agents against Asian gov/edu networks. HIGH urgency.
The Gentlemen Ransomware Group — TukTuk C2 v2.0 Framework & EDRKiller BYOVD Toolkit: OTX Pulse Analysis + Enterprise Detection Pack
OTX pulse exposes The Gentlemen's TukTuk C2 v2.0 framework with cross-platform agents and EDR-neutralization toolkit targeting US defense, healthcare, and aerospace. Hunt and block now.
Woodgnat Node.js Abuse Campaign: ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix — OTX Detection Pack
Woodgnat actor abuses signed node.exe to run ModeloRAT, AsukaStealer & AdaptixC2 via ClickFix lures. 180 IOCs, EtherHiding C2. Immediate hunt required.
Tampered Exodus Wallet Installer Drops Modular RAT: Dll4 Suite Credential Theft Campaign — OTX Detection Pack
Fake Exodus crypto wallet installers are deploying a six-module RAT (Dll4_*) via JavaScript droppers and Azure Table Storage C2. High urgency — hunt now.
Knight Office M365 AiTM Kit + Tampered Exodus Modular RAT: OTX Pulse Analysis — Session Token Theft and Credential Access Detection Pack
OTX pulses detail M365 AiTM session-token phishing and a fake Exodus wallet modular RAT using Azure-backed C2. Enterprise identity and crypto-adjacent users face elevated credential-theft risk.
Zer0day Stealer, StreamRat, Knight Office AiTM + Exodus RAT: OTX Credential-Theft Detection Pack
OTX flags AiTM M365 token theft, Android banking takeover, Rust infostealer/RAT pipeline and trojanized Exodus RAT; reset credentials now.
Sality Botnet Sinkhole & Tampered Exodus Wallet Modular RAT: OTX Pulse Analysis — Infostealer & Credential Theft Detection Pack
OTX pulses reveal the Sality P2P botnet takedown (EggJagger clipper delivery) and a modular RAT hidden in fake Exodus wallet installers. Credential and crypto theft at scale. Urgent.
Packagist Supply-Chain iOS Spyware Chain (CVE-2025-31277 / CVE-2025-43529): FunNULL-Linked Crypto Seed Theft — OTX Pulse Analysis
13 malicious Packagist Composer themes inject JS delivering iOS WebKit-to-kernel spyware that steals crypto wallet seeds. FunNULL infrastructure implicated. URGENT.
BraZetsu IAB Framework & Packagist iOS Spyware Chain: OTX Pulse Analysis — Exilware Initial Access + Supply Chain Credential Theft Detection Pack
OTX pulses expose Exilware's BraZetsu Python IAB framework targeting LATAM/Iberian finance, plus 13 malicious Packagist themes weaponizing iOS WebKit CVEs for crypto seed theft. Urgent hunt advised.
JSCeal V8 Bytecode Cryptocurrency Stealer: Compiled Node.js Infostealer Evading Static Analysis — OTX Pulse Detection Pack
OTX pulse exposes JSCeal, a cryptocurrency-focused infostealer shipped as compiled V8 bytecode with RC4 string encryption, control-flow flattening, and MITM browser theft. High urgency for SOC hunting.
Blind Eagle (APT-C-36) GitHub Loader Pipeline: AsyncRAT, DcRat, Remcos & XWorm Targeting Colombian Government — OTX Detection Pack
OTX pulse exposes Blind Eagle operator staging AsyncRAT, DcRat, Remcos & XWorm via GitHub loaders against Colombian government. IOCs + Sigma/KQL detections inside.
AnonyMousKIT AI-Powered PhaaS Supply Chain: OTX Pulse Analysis — Apple Activation Lock Credential Harvesting Detection Pack
AnonyMousKIT PhaaS platform uses AI vishing and multi-channel phishing across 506 domains to steal Apple credentials and disable Activation Lock. High urgency for government and education sectors.
DARKLANTERN/SPEAKINGSTONE Implants, Evilginx AiTM & AnonyMousKIT PhaaS: OTX Credential-Theft Detection Pack
OTX pulses expose converging credential theft: malicious browser extensions, ZBT firmware implants, AI PhaaS and Evilginx AiTM. Block IOCs, reset exposed sessions, harden edge now.
Dysphoria Blockchain-C2 Botnet, Browser-Extension Wallet Drainers & AnonyMousKIT PhaaS: OTX Credential-Theft Campaign Analysis — Enterprise Detection Pack
OTX exposes converging credential-theft ops: Dysphoria botnet, 19 wallet-draining browser extensions, ZBT implants, and AnonyMousKIT PhaaS. Hunt immediately.
pepesoft.exe Infostealer + ZBT Firmware Implants + XenoRAT Spear-Phishing: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal NuGet supply-chain infostealers, ZBT router firmware backdoors, Kimsuky XenoRAT campaigns, and browser wallet drainers. Immediate IOC blocking and credential rotation required.
DEV#POPPER npm Supply Chain RAT, SectopRAT Fake Claude Installers & 19-Extension Wallet Drainer: OTX Pulse Analysis — Blockchain C2 & Credential Theft Detection Pack
OTX pulses reveal npm supply-chain RAT delivery, malvertised fake Claude Desktop installers, and 19 malicious browser extensions — all stealing credentials via blockchain-backed C2. URGENT.
CastleLoader/NeedleStealer, MCP AI-Agent Exploitation and RecruitTrap Mobile OAuth Theft: OTX Enterprise Detection Pack
OTX pulses show credential-theft convergence: CastleLoader/NeedleStealer chains, MCP honeypot abuse, and RecruitTrap mobile OAuth phishing. Enterprise identity and browser secrets are at immediate risk.
GoCaracal + Bandook C2, MCP Secrets Abuse, and RecruitTrap OAuth Phishing: OTX Pulse Detection Pack — 2026-08-26
OTX shows converged credential theft: Dark Caracal espionage in LatAm telecom, MCP/AI-agent secrets abuse, and RecruitTrap mobile OAuth phishing. Hunt and block now.
AMOS Stealer EtherHiding C2, EKZ Stealer via Fortinet CVE-2026-35616 & RecruitTrap OAuth Phishing: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal AMOS/XMRig macOS ClickFix campaign with blockchain C2, EKZ Stealer deployed via Fortinet EMS CVE-2026-35616, and RecruitTrap credential phishing. Enterprise detection pack included.
Rhadamanthys Stealer + RecruitTrap Phishing Kit: OTX Pulse Analysis — AI-Generated Malware & OAuth Token Theft Detection Pack
OTX pulses reveal AI-assisted infostealers (Rhadamanthys, Oyster) reaching endpoints and RecruitTrap recruitment phishing harvesting enterprise OAuth tokens on mobile. High urgency.
Vidar Infostealer via Fake GTA 6 Lures, HookBot/ERMAC Leak Fallout & RecruitTrap OAuth Phishing: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses flag Vidar stealer in fake GTA 6 demo sites, HookBot/ERMAC source-leak panels, and RecruitTrap OAuth phishing hitting enterprise credentials. Hunt now.
SysScan Fake AV Scam Network + RecruitTrap Mobile Credential Phishing: OTX Pulse Analysis — Enterprise Detection Pack
Two concurrent social-engineering campaigns — SysScan fake security scans and RecruitTrap recruitment phishing — are stripping endpoint defenses and harvesting enterprise credentials. Hunt now.
Education Sector Credential Harvesting Surge: Typosquat Phishing Infrastructure Targeting Students — OTX Pulse Analysis & Detection Pack
4,696 weekly attacks per education org; typosquat phishing domains harvesting student credentials. High urgency for EDU, gov, retail sectors.
IOCONTROL + MALPDB PLC Sabotage Campaign & Education Credential-Phishing Surge: OTX Pulse Analysis — Enterprise Detection Pack
Cyber Av3ngers exploiting internet-exposed PLCs via legitimate engineering software; parallel phishing surge hitting education with 4,696 weekly attacks. Critical urgency for OT/energy and EDU sectors.
BRIDGEHEAD npm Typosquat + proc-macro1 Rust Crate Compromise: Supply-Chain Credential Theft Campaign — OTX Detection Pack
OTX pulses reveal twin supply-chain infostealer ops: 40 typosquatted npm packages and compromised Rust crates delivering in-memory crypto-wallet and credential stealers.
Hermes AI-Driven Espionage, N4D go-titan & Supply Chain Credential Theft: OTX Pulse Detection Pack
Autonomous AI attack agent Hades targets Thai finance ministry; npm/Rust typosquats and Void Blizzard Zimbra zero-click phishing drive credential theft at scale. HIGH urgency.
FakeAgent Malvertising + SectopRAT/StealC, npm/Rust Supply Chain Stealers & N4D Mesh Controller: OTX Pulse Analysis — Enterprise Detection Pack
CRITICAL: Claude AI malvertising delivers SectopRAT/StealC to 29 orgs; npm & Rust crates compromised for credential theft; N4D botnet exploits MCP servers. Block IOCs now.
SynkLoader, BRIDGEHEAD & N4D Mesh: Cross-Platform Credential Theft Wave — OTX Pulse Analysis & Enterprise Detection Pack
OTX pulses reveal converging credential-theft campaigns: Teams-phished SynkLoader, npm/Rust supply-chain stealers, and N4D/NadMesh botnets hunting AI infrastructure keys. High urgency.
AMOS Stealer, N4D Mesh Controller & 'BRIDGEHEAD' npm Campaign: OTX Pulse Analysis — Infostealer Detection Pack for Enterprise SOCs
OTX pulses reveal five active credential-theft campaigns: ClickFix macOS stealers, npm typosquatting, N4D Linux malware, malicious Firefox extensions, and education phishing. URGENT: hunt now.
Operation STANDOFF + Offside Wallet Theft Factory: GitHub-Redirected C2, Stealer Loader Chains & Malicious Firefox Extensions — OTX Enterprise Detection Pack
OTX reveals two active campaigns: Operation STANDOFF's Russian-speaking loader distributing Raccoon/RedLine/Amadey via GitHub-redirected C2, and 77 malicious Firefox extensions stealing crypto wallets and credentials. Immediate hunting required.
ClickFix Fileless Infostealers, JADEPUFFER AI-Targeting Ransomware & Balonx PhaaS: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses reveal ClickFix fake-CAPTCHA infostealer evolution, JADEPUFFER's AI-destroying ENCFORGE ransomware, Mexican banking PhaaS, and 77 malicious Firefox extensions. HIGH urgency — credential theft at scale.
Mirage2FA AitM Phishing-as-a-Service: Microsoft 365 Session Hijacking Campaign (LinX Coders) — OTX Detection Pack
Mirage2FA PhaaS kit hijacks Microsoft 365 sessions via AitM proxying & HTML smuggling — 4K+ US victims. IOCs, Sigma, KQL and hunt scripts inside.
ClickFix RAT MaaS, Kimsuky Gomir Variants & Mirage2FA AiTM Phishing: OTX Pulse Analysis — Enterprise Detection Pack
LIVE OTX: ClickFix-delivered NodeJS RAT over Tor gRPC, Kimsuky BirdTroy/DriveTroy supply-chain intrusions, and Mirage2FA AiTM phishing hitting 4K+ US M365 tenants.
PhantomStealer Injector + Mirage2FA AitM PhaaS: OTX Pulse Analysis — Credential Theft Detection Pack
OTX pulses reveal PhantomStealer UAC-bypass injectors via quote-phishing and Mirage2FA AitM kit hijacking 4K+ M365 sessions. Hunt and block now.
Octagon Android Banking Bot (MaaS): AndroidKitKat's Crypto-Stealing Trojan — OTX Pulse Analysis & Detection Pack
Octagon, a $1,400/month Android MaaS fraud bot from AndroidKitKat, targets crypto wallets and banking apps via accessibility abuse, HVNC, and overlays.
Blind Eagle (APT-C-36) Evolved Toolkit: AsyncRAT, njRAT & LimeRAT via AutoIt RunPE and DuckDNS C2 — OTX Detection Pack
Blind Eagle (APT-C-36) fields evolved AsyncRAT/njRAT toolkit — VBScript droppers, AutoIt RunPE loaders, DuckDNS C2 — targeting Colombian finance. High urgency.
NadMesh Botnet: Go-Based AI Infrastructure Credential Harvester — OTX Pulse Analysis & Enterprise Detection Pack
NadMesh, an industrial-grade Go botnet, is autonomously exploiting AI/cloud infrastructure (Redis, Docker, Kubernetes, MCP) across 90+ cloud provider ranges. Immediate IOC blocking and credential rotation advised.
Lua Loader Infostealer Campaign + GoSerpent APT Backdoor: OTX Pulse Analysis — Agent Tesla, XWorm & Southeast Asia Government Targeting Detection Pack
OTX pulses expose a global Lua-loader phishing campaign dropping Agent Tesla, Remcos, XWorm, and Snake Keylogger, plus TetrisPhantom's GoSerpent RAT hitting SE Asian governments. High urgency.
Starland RAT + WLDR Implant & Spirals Ransomware: OTX Pulse Analysis — UAT-11795 ClickFix Campaign and Rust-Based Double Extortion Detection Pack
OTX pulses reveal UAT-11795's Starland RAT/WLDR ClickFix campaign targeting US/EU credentials and crypto, plus novel Rust-based Spirals ransomware hitting Asian IT firms. Act now.
Tomorrowland 2026 Fake Ticket Shop Network: Phishing & Payment Fraud Infrastructure — OTX Pulse Analysis and Detection Pack
~12 fraudulent domains impersonating Tomorrowland 2026 target ticket seekers in EU with phishing, payment fraud & fake biometric checks. Urgent blocking advised.
Miasma Worm v3 npm Supply-Chain Attack + Tomorrowland Credential-Harvesting Scam Network: OTX Pulse Analysis — Detection Pack
OTX pulses expose Miasma v3 worm delivered via hijacked AsyncAPI npm packages and a 12-domain Tomorrowland phishing ring harvesting credentials and payments across the EU. Hunt now.
PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Espionage + Linux Botnet Credential Theft — OTX Detection Pack
OTX pulses expose PATCHCORD backdoor hitting Afghan telecom, Evooo1Bot Linux botnet, Miasma v3 npm supply-chain worm & Tomorrowland phishing. Full detection pack.
Multi-Stage Phishing Relay Chains + Tomorrowland 2026 Festival Fraud: Cloudflare Workers Abuse, HTML Smuggling & Typosquat Campaign — OTX Detection Pack
OTX pulses reveal multi-stage phishing chains abusing Cloudflare Workers/Framer with HTML smuggling, plus a dozen typosquat domains running fake Tomorrowland 2026 ticket scams. Block now.
Kratos PhaaS, Multi-Stage Redirect Chains & Festival Ticket Fraud: OTX Pulse Analysis — M365 Credential Theft Detection Pack
Kratos PhaaS kit, Cloudflare Workers/Framer redirect chains, and fake Tomorrowland ticket shops are harvesting M365 and payment credentials across US/EU. Urgent: hunt now.
Armored Likho Still Toolkit (Rust) + Multi-Stage Phishing Relay Chains: OTX Pulse Analysis — Enterprise Detection Pack
OTX pulses expose Armored Likho's Rust-based Still Toolkit targeting Telegram & audio surveillance, plus multi-stage phishing relays abusing Cloudflare Workers. High urgency.
CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack
OTX pulses expose Midnight Blizzard's hotel Wi-Fi captive portal credential theft (CornFlake/ChocoShell) and UNC6671's multi-brand vishing extortion. Urgent: block IOCs, reset M365 creds.
Aeternum Blockchain C2, ErrTraffic ClickFix, CaptiveCrunch M365 Phishing, GoldDigger Android: OTX Enterprise Detection Pack
OTX pulses reveal blockchain-C2 infostealers, ClickFix/EtherHiding loaders, hotel captive-portal M365 credential phishing, and GoldDigger Android banking trojan activity. High urgency for identity and endpoint hunting.
Midnight Blizzard CaptiveCrunch, codemado AiTM Phishing Stack, GhostDesk Spyware & WP-SHELLSTORM Webshell Botnet: OTX Pulse Analysis — Credential Theft Detection Pack
Live OTX pulses expose APT29 hotel Wi-Fi credential theft, a triple-operator AiTM phishing platform, fake CCleaner Chrome spyware, and 1.4M WordPress webshell campaign. Critical urgency.
Showing 50 of 363 reports. Archive expands automatically as new intel is generated.
Every Credential LeaksReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.