#credentialharvesting — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #credentialharvesting, aggregated by home.social.
-
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline
A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...
Pulse ID: 6aba46a30e26418fb09c6000
Pulse Link: https://otx.alienvault.com/pulse/6aba46a30e26418fb09c6000
Pulse Author: AlienVault
Created: 2026-09-28 10:51:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault
-
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline
A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...
Pulse ID: 6aba46a30e26418fb09c6000
Pulse Link: https://otx.alienvault.com/pulse/6aba46a30e26418fb09c6000
Pulse Author: AlienVault
Created: 2026-09-28 10:51:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault
-
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline
A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...
Pulse ID: 6aba46a30e26418fb09c6000
Pulse Link: https://otx.alienvault.com/pulse/6aba46a30e26418fb09c6000
Pulse Author: AlienVault
Created: 2026-09-28 10:51:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault
-
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline
A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...
Pulse ID: 6aba46a30e26418fb09c6000
Pulse Link: https://otx.alienvault.com/pulse/6aba46a30e26418fb09c6000
Pulse Author: AlienVault
Created: 2026-09-28 10:51:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault
-
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline
A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...
Pulse ID: 6aba46a30e26418fb09c6000
Pulse Link: https://otx.alienvault.com/pulse/6aba46a30e26418fb09c6000
Pulse Author: AlienVault
Created: 2026-09-28 10:51:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault