home.social

#credentialharvesting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #credentialharvesting, aggregated by home.social.

  1. Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access

    Attackers who gain access to AWS credentials perform validation to determine their usefulness, particularly for Amazon Bedrock access. Multiple credential harvesting platforms, including KMON_NOC, have been identified that specifically test stolen AWS keys for LLM capabilities. These platforms validate credentials using GetCallerIdentity, then test Bedrock access through ListFoundationModels and Converse API calls. The validation process helps attackers assess credential value for resale in token-jacking markets, where stolen AI model access is sold below retail price. Scripts analyzed on VirusTotal demonstrate systematic testing across multiple regions, targeting Anthropic Claude models specifically, and enumerating promotional credits to assess financial value. This represents an evolution in credential validation similar to historical patterns observed with AWS SES/SNS services.

    Pulse ID: 6ac52c8896a61ee777d4aee5
    Pulse Link: otx.alienvault.com/pulse/6ac52
    Pulse Author: AlienVault
    Created: 2026-10-06 17:14:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amazon #AWS #CredentialHarvesting #VirusTotal #OTX #AlienVault

  2. Iranian State-Aligned Threat Actor Masquerading as Dubai Airports IT Department Delivering Trojanized Coding Challenges - Blinder Tunnel Campaign Targeting Iraqi Critical Infrastructure

    An Iranian state-aligned threat actor designated as CL-STA-1178 has been impersonating the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. The Blinder Tunnel campaign, active since November 2025 with attacks intensifying in March 2026, primarily targeted Iraqi critical infrastructure. The operation employs a three-step attack chain exploiting legitimate Windows developer files, AppDomainManager hijacking, and DLL sideloading to deploy ShelbyLoader V2 malware. Attackers abuse GitHub API infrastructure for command-and-control communications, utilizing repositories for decryption keys, payload downloads, and GitHub issues as fallback mechanisms. The campaign incorporates Peaky Blinders television show themes in its infrastructure naming and embeds the show's theme song in malware. Operational security failures exposed connections to a separate credential harvesting operation targeting Israeli entities using conflict-themed Google Drive lures during May-June 2026.

    Pulse ID: 6ac6152430b84019d1fded71
    Pulse Link: otx.alienvault.com/pulse/6ac61
    Pulse Author: AlienVault
    Created: 2026-10-07 09:47:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #Deliver #Deploy #GitHub #OTX #AlienVault

  3. Gentlemen Ransomware Campaign Abuses MCP for Command Execution

    Gentlemen ransomware affiliate Azazel abused Model Context Protocol
    (MCP) tooling as a command and control channel during live intrusions. The
    campaign targeted GitLab secrets, credentials and cloud infrastructure, using
    MCP-based command execution, credential harvesting, data exfiltration and
    destructive actions across compromised environments.

    Pulse ID: 6ac56b9663bd025854777de2
    Pulse Link: otx.alienvault.com/pulse/6ac56
    Pulse Author: cryptocti
    Created: 2026-10-06 21:43:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Gentlemen #RansomWare #Cloud #CredentialHarvesting #OTX #cryptocti

Share on Mastodon

Enter the server where you have an account.