home.social

#credentialharvesting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #credentialharvesting, aggregated by home.social.

  1. Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline

    A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...

    Pulse ID: 6aba46a30e26418fb09c6000
    Pulse Link: otx.alienvault.com/pulse/6aba4
    Pulse Author: AlienVault
    Created: 2026-09-28 10:51:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault

  2. Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline

    A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...

    Pulse ID: 6aba46a30e26418fb09c6000
    Pulse Link: otx.alienvault.com/pulse/6aba4
    Pulse Author: AlienVault
    Created: 2026-09-28 10:51:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault

  3. Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline

    A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...

    Pulse ID: 6aba46a30e26418fb09c6000
    Pulse Link: otx.alienvault.com/pulse/6aba4
    Pulse Author: AlienVault
    Created: 2026-09-28 10:51:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault

  4. Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline

    A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...

    Pulse ID: 6aba46a30e26418fb09c6000
    Pulse Link: otx.alienvault.com/pulse/6aba4
    Pulse Author: AlienVault
    Created: 2026-09-28 10:51:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault

  5. Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline

    A sophisticated cybercrime operation compromised enterprise networks across multiple countries by exploiting a GlobalProtect authentication bypass vulnerability (CVE-2026-0257), executed advanced web application attacks, and deployed the AdaptixC2 framework. The operation scanned 277.5 million addresses to curate 81 high-value targets, stole databases from 9+ instances via SQL injection with xp_cmdshell escalation, and exfiltrated Active Directory credentials. Monetization occurred through dual strategies: initially selling corporate and energy sector databases on underground forums under the persona "masterblack", then weaponizing the same data to power a multi-tenant automated invoice fraud platform generating 2.4 million phishing messages and 622,666 personalized fraudulent links. The infrastructure utilized domainless phishing tactics including M365 OAuth device-code phishing and voice-based credential harvesting, collecting payments via PIX through serverless proxies. The operation was exposed in mid-...

    Pulse ID: 6aba46a30e26418fb09c6000
    Pulse Link: otx.alienvault.com/pulse/6aba4
    Pulse Author: AlienVault
    Created: 2026-09-28 10:51:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CVE20260257 #CredentialHarvesting #CyberCrime #Phishing #OTX #AlienVault