Hundreds Of Network Operators’ Credentials Found Circulating In Dark Web
ID: 04cc4ce8-a594-5a57-bb3b-1bee328f40fe
STIX ID: report--04cc4ce8-a594-5a57-bb3b-1bee328f40fe
Feed Name: infostealers.com
Resecurity details the January 2024 Orange España incident in which an attacker ('Snow') used credentials stolen by infostealer malware to hijack a RIPE NCC account and deliberately misconfigure BGP and RPKI, causing a multi-hour outage; the report also reveals 1,572 compromised registry credentials discovered on the dark web across RIPE, APNIC, AFRINIC and LACNIC, highlights widespread infostealer activity targeting telecom engineers, and urges stronger credential hygiene and mandatory MFA for registry accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
