home.social

#credentialharvesting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #credentialharvesting, aggregated by home.social.

  1. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

    Pulse ID: 6a9af7a5158ae188847551b5
    Pulse Link: otx.alienvault.com/pulse/6a9af
    Pulse Author: AlienVault
    Created: 2026-09-04 16:53:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #BackDoor #CredentialHarvesting #CyberSecurity #DPRK #Encryption #HTTP #InfoSec #KeyLogger #Korea #Linux #Nim #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteCommandExecution #SSH #SSL #SouthKorea #Trojan #bot #AlienVault

  2. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

    Pulse ID: 6a9af7a5158ae188847551b5
    Pulse Link: otx.alienvault.com/pulse/6a9af
    Pulse Author: AlienVault
    Created: 2026-09-04 16:53:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #BackDoor #CredentialHarvesting #CyberSecurity #DPRK #Encryption #HTTP #InfoSec #KeyLogger #Korea #Linux #Nim #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteCommandExecution #SSH #SSL #SouthKorea #Trojan #bot #AlienVault

  3. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

    Pulse ID: 6a9af7a5158ae188847551b5
    Pulse Link: otx.alienvault.com/pulse/6a9af
    Pulse Author: AlienVault
    Created: 2026-09-04 16:53:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #BackDoor #CredentialHarvesting #CyberSecurity #DPRK #Encryption #HTTP #InfoSec #KeyLogger #Korea #Linux #Nim #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteCommandExecution #SSH #SSL #SouthKorea #Trojan #bot #AlienVault

  4. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

    Pulse ID: 6a9af7a5158ae188847551b5
    Pulse Link: otx.alienvault.com/pulse/6a9af
    Pulse Author: AlienVault
    Created: 2026-09-04 16:53:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #BackDoor #CredentialHarvesting #CyberSecurity #DPRK #Encryption #HTTP #InfoSec #KeyLogger #Korea #Linux #Nim #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteCommandExecution #SSH #SSL #SouthKorea #Trojan #bot #AlienVault

  5. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

    Pulse ID: 6a9af7a5158ae188847551b5
    Pulse Link: otx.alienvault.com/pulse/6a9af
    Pulse Author: AlienVault
    Created: 2026-09-04 16:53:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #BackDoor #CredentialHarvesting #CyberSecurity #DPRK #Encryption #HTTP #InfoSec #KeyLogger #Korea #Linux #Nim #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteCommandExecution #SSH #SSL #SouthKorea #Trojan #bot #AlienVault

  6. AI-Powered PhaaS Supply Chain

    AnonyMousKIT is an AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. Operating as a credit-metered system, it automates credential harvesting through email, SMS, WhatsApp, and AI-driven voice phishing calls. The investigation exposed a reseller supply chain spanning 506 domains and 168 storefront brands active since early 2024. The platform targets owners of stolen Apple devices using device-specific lures with internal model identifiers and real-time Find My statuses. Conversational AI agents impersonating Apple Support conduct vishing operations, with over 200 calls placed primarily to Brazil at minimal cost. Coding vulnerabilities exposed 120,242 lines of operational logs, revealing 689 distinct WhatsApp operator accounts and detailed attack infrastructure. The ecosystem operates through a decentralized enterprise structure with developers, resellers, and hundreds of subscriber-operators monetizing stolen iPhone hardware through industrialized soc...

    Pulse ID: 6a8fefa73dcdd0e3c18df580
    Pulse Link: otx.alienvault.com/pulse/6a8fe
    Pulse Author: AlienVault
    Created: 2026-08-27 08:04:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CredentialHarvesting #CyberSecurity #Email #InfoSec #Nim #OTX #OpenThreatExchange #Phishing #RAT #SMS #SupplyChain #WhatsApp #bot #developers #AlienVault

  7. AI-Powered PhaaS Supply Chain

    AnonyMousKIT is an AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. Operating as a credit-metered system, it automates credential harvesting through email, SMS, WhatsApp, and AI-driven voice phishing calls. The investigation exposed a reseller supply chain spanning 506 domains and 168 storefront brands active since early 2024. The platform targets owners of stolen Apple devices using device-specific lures with internal model identifiers and real-time Find My statuses. Conversational AI agents impersonating Apple Support conduct vishing operations, with over 200 calls placed primarily to Brazil at minimal cost. Coding vulnerabilities exposed 120,242 lines of operational logs, revealing 689 distinct WhatsApp operator accounts and detailed attack infrastructure. The ecosystem operates through a decentralized enterprise structure with developers, resellers, and hundreds of subscriber-operators monetizing stolen iPhone hardware through industrialized soc...

    Pulse ID: 6a8fefa73dcdd0e3c18df580
    Pulse Link: otx.alienvault.com/pulse/6a8fe
    Pulse Author: AlienVault
    Created: 2026-08-27 08:04:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CredentialHarvesting #CyberSecurity #Email #InfoSec #Nim #OTX #OpenThreatExchange #Phishing #RAT #SMS #SupplyChain #WhatsApp #bot #developers #AlienVault

  8. AI-Powered PhaaS Supply Chain

    AnonyMousKIT is an AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. Operating as a credit-metered system, it automates credential harvesting through email, SMS, WhatsApp, and AI-driven voice phishing calls. The investigation exposed a reseller supply chain spanning 506 domains and 168 storefront brands active since early 2024. The platform targets owners of stolen Apple devices using device-specific lures with internal model identifiers and real-time Find My statuses. Conversational AI agents impersonating Apple Support conduct vishing operations, with over 200 calls placed primarily to Brazil at minimal cost. Coding vulnerabilities exposed 120,242 lines of operational logs, revealing 689 distinct WhatsApp operator accounts and detailed attack infrastructure. The ecosystem operates through a decentralized enterprise structure with developers, resellers, and hundreds of subscriber-operators monetizing stolen iPhone hardware through industrialized soc...

    Pulse ID: 6a8fefa73dcdd0e3c18df580
    Pulse Link: otx.alienvault.com/pulse/6a8fe
    Pulse Author: AlienVault
    Created: 2026-08-27 08:04:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CredentialHarvesting #CyberSecurity #Email #InfoSec #Nim #OTX #OpenThreatExchange #Phishing #RAT #SMS #SupplyChain #WhatsApp #bot #developers #AlienVault

  9. AI-Powered PhaaS Supply Chain

    AnonyMousKIT is an AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. Operating as a credit-metered system, it automates credential harvesting through email, SMS, WhatsApp, and AI-driven voice phishing calls. The investigation exposed a reseller supply chain spanning 506 domains and 168 storefront brands active since early 2024. The platform targets owners of stolen Apple devices using device-specific lures with internal model identifiers and real-time Find My statuses. Conversational AI agents impersonating Apple Support conduct vishing operations, with over 200 calls placed primarily to Brazil at minimal cost. Coding vulnerabilities exposed 120,242 lines of operational logs, revealing 689 distinct WhatsApp operator accounts and detailed attack infrastructure. The ecosystem operates through a decentralized enterprise structure with developers, resellers, and hundreds of subscriber-operators monetizing stolen iPhone hardware through industrialized soc...

    Pulse ID: 6a8fefa73dcdd0e3c18df580
    Pulse Link: otx.alienvault.com/pulse/6a8fe
    Pulse Author: AlienVault
    Created: 2026-08-27 08:04:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CredentialHarvesting #CyberSecurity #Email #InfoSec #Nim #OTX #OpenThreatExchange #Phishing #RAT #SMS #SupplyChain #WhatsApp #bot #developers #AlienVault

  10. AI-Powered PhaaS Supply Chain

    AnonyMousKIT is an AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. Operating as a credit-metered system, it automates credential harvesting through email, SMS, WhatsApp, and AI-driven voice phishing calls. The investigation exposed a reseller supply chain spanning 506 domains and 168 storefront brands active since early 2024. The platform targets owners of stolen Apple devices using device-specific lures with internal model identifiers and real-time Find My statuses. Conversational AI agents impersonating Apple Support conduct vishing operations, with over 200 calls placed primarily to Brazil at minimal cost. Coding vulnerabilities exposed 120,242 lines of operational logs, revealing 689 distinct WhatsApp operator accounts and detailed attack infrastructure. The ecosystem operates through a decentralized enterprise structure with developers, resellers, and hundreds of subscriber-operators monetizing stolen iPhone hardware through industrialized soc...

    Pulse ID: 6a8fefa73dcdd0e3c18df580
    Pulse Link: otx.alienvault.com/pulse/6a8fe
    Pulse Author: AlienVault
    Created: 2026-08-27 08:04:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CredentialHarvesting #CyberSecurity #Email #InfoSec #Nim #OTX #OpenThreatExchange #Phishing #RAT #SMS #SupplyChain #WhatsApp #bot #developers #AlienVault