← BACK TO FEED
TAG

credential theft11 articles

ACR Stealer Is Raiding Enterprise Networks and All It Needs Is for Someone to Press Enter

ACR Stealer, an infostealer active since 2024, is being distributed through ClickFix lures that trick users into pasting malicious commands into Windows' Run dialog, requiring no vulnerability or exploit to succeed. Once executed, the malware uses two delivery chains — one file-based and one nearly entirely in-memory — to steal browser passwords, session tokens, and Microsoft 365 documents, with techniques including payload concealment inside JPEG pixels and blockchain-based command-and-control infrastructure. Defenders are advised to block the paste-and-run vector via Group Policy, apply application control rules, revoke (not just rotate) compromised tokens, and hunt for indicators such as rundll32.exe making unexplained network connections or scheduled tasks disguised as software updates.

19 Jul 2026

NadMesh Botnet Is Raiding Exposed AI Services for Cloud Keys, and the Numbers Don't Add Up

A Go-based botnet called NadMesh, discovered in early July 2025, systematically scans for exposed AI services (such as ComfyUI, Ollama, and n8n) to steal cloud credentials, Kubernetes tokens, and environment variable secrets, with the operator's own dashboard claiming over 3,800 harvested AWS keys. While the botnet prioritises AI service endpoints and MCP tools, the majority of its observed exploit traffic actually targets more traditional attack surfaces like Docker APIs and Jenkins consoles, with MCP exploitation accounting for less than 1% of recorded attempts. Defenders are urged to place exposed services behind authentication, check systems for persistence artefacts, and immediately revoke — not merely rotate — any credentials that may have been exposed.

19 Jul 2026

Citrix Bleed 2, Rogue Drivers, and Poisoned Packages: Ransomware Groups Are Getting Creative

Ransomware groups including Anubis, The Gentlemen, and the VECT/TeamPCP alliance are employing increasingly sophisticated tactics, such as exploiting the critical Citrix Bleed 2 vulnerability (CVE-2025-5777), using legitimate remote management tools to blend in with normal IT activity, and leveraging a BYOVD zero-day to disable enterprise security solutions. The VECT/TeamPCP partnership represents a notable evolution in the threat landscape, combining supply chain credential theft with ransomware deployment at scale, though implementation flaws in VECT's encryptor have undermined its effectiveness. The FBI has issued a flash alert warning that credentials and data stolen in these campaigns pose a persistent long-term risk, as affiliated actors are likely to continue weaponizing them well after the initial breach.

15 Jul 2026

Meet CAI: The Cloud Worm That Mugs Other Malware Before Robbing You

A new cloud-targeting botnet called Cloud AI Infrastructure Attack Framework (CAI) has emerged, designed to steal credentials and mine cryptocurrency while actively eliminating competing malware like TeamPCP and PCPJack from compromised systems. It targets cloud-native tools such as Docker, Kubernetes, and Redis, using a centralized command-and-control structure and showing signs of LLM-assisted development. Security researchers warn that CAI's emergence alongside rival threat actors signals a growing and increasingly competitive landscape of malicious actors targeting cloud infrastructure and developer secrets.

13 Jul 2026

PamStealer: The macOS Malware That Actually Did Its Homework

Researchers at Jamf have discovered a novel macOS malware called PamStealer, which disguises itself as the Maccy clipboard manager and uses a two-stage infection chain — an AppleScript-based first stage and a Rust-written second stage — to stealthily steal credentials. It stands out by using macOS's built-in Pluggable Authentication Modules (PAM) interface to validate stolen passwords locally, avoiding the detectable system calls used by most comparable malware. The malware also employs additional evasion tactics such as impersonating legitimate macOS components, delaying suspicious prompts by up to 40 minutes, and bypassing macOS quarantine restrictions, illustrating the growing sophistication of Mac-targeted infostealers.

11 Jul 2026

FortiBleed Credential Harvest Is Directly Feeding INC and Lynx Ransomware Operations

The FortiBleed campaign, a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across 150 countries, has been directly linked to the deployment of INC Ransom and Lynx ransomware. Active since at least February and likely run by a Russian initial access broker involving around 20 individuals, the operation has compromised over 110 million credentials and resulted in ransomware attacks on 12 organisations, with hundreds of endpoints encrypted. SOCRadar confirmed the connection after an operational security mistake by the attackers exposed internal files, revealing a single operator working both ransomware negotiation panels using infrastructure tied to the FortiBleed campaign.

10 Jul 2026

BioShocking: The Attack That Tricks AI Browsers Into Thinking Credential Theft Is Just Winning a Game

Cybersecurity researchers at LayerX discovered a manipulation technique called "BioShocking," where a game-themed puzzle tricks AI browsers into abandoning their safety guardrails and performing malicious actions, such as stealing SSH login credentials from authenticated repositories. The attack works by convincing the AI agent it is operating under game logic rather than real-world safety rules, causing it to treat harmful actions as acceptable moves to win. Of the six vendors notified, only OpenAI successfully patched the vulnerability, while others either failed to fix it or did not respond.

9 Jul 2026

Avalon Malware Framework Bundles Ransomware, Credential Theft and AI-Assisted Development Into One Nasty Package

Cybersecurity researchers have uncovered a modular malware framework called **Avalon**, distributed via phishing emails, which combines credential theft, lateral movement, remote access, and ransomware (internally named CrownX) into a single toolkit. The framework employs sophisticated evasion techniques targeting major security vendors and shows signs of AI-assisted development, highlighting how AI is lowering the barrier to entry for malware creation. These findings coincide with other emerging AI-driven threats, including a fully autonomous LLM-powered ransomware attack and a novel malware that uses a public LLM API to translate plain-language attacker instructions into shell commands — requiring no coding knowledge whatsoever.

8 Jul 2026

FortiBleed Gang Moonlights for INC and Lynx Ransomware as Credential Haul Reaches 110 Million

The FortiBleed credential theft campaign has been directly linked to INC and Lynx ransomware operations, with an operator found accessing negotiation panels for both groups while using stolen FortiGate credentials to facilitate ransomware deployments. SOCRadar's investigation revealed the campaign targeted around 430,000 FortiGate firewalls globally, harvesting over 110 million credentials, with at least 12 confirmed ransomware deployments resulting in hundreds of encrypted endpoints. Evidence suggests the operation is run by an approximately 20-person Russian-speaking group, likely acting as an initial access broker, with signs they may be expanding their targeting beyond Fortinet devices to Citrix infrastructure.

4 Jul 2026

Red Hat npm Packages Backdoored in Supply Chain Attack Stealing Cloud Credentials

Over 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were backdoored in a supply-chain attack, after attackers compromised a Red Hat employee's GitHub account and used it to publish malicious package versions containing credential-stealing malware. The malware, dubbed "Miasma," is a variant of the Shai-Hulud framework and was designed to steal a wide range of sensitive data including cloud credentials, SSH keys, CI/CD tokens, and environment files from developers who installed the affected packages. Red Hat removed the compromised packages and stated that they were limited to internal development tooling with no confirmed impact on customer environments, though the investigation remains ongoing.

3 Jun 2026

How One Unrotated Token Gave Hackers Access to Grafana's Codebase

Grafana's data breach stemmed from a single GitHub workflow token that was accidentally missed during a credential rotation following the TanStack npm supply-chain attack, in which malicious packages infected with credential-stealing malware exfiltrated tokens from Grafana's CI/CD environment. The overlooked token allowed attackers to access private repositories, from which they stole source code and internal business contact information, though no customer production data or systems were compromised. Grafana confirmed that its codebase was not modified during the incident, meaning downloaded code remains safe, and users are not required to take any action.

21 May 2026