How Infostealers Industrialize the Brute-Forcing of Corporate SSO Gateways
ID: a08a5205-4130-5e36-8ab6-71710b5174ed
STIX ID: report--a08a5205-4130-5e36-8ab6-71710b5174ed
Feed Name: infostealers.com
Threat Score
This report details a credential-stuffing campaign that leveraged Infostealer-harvested credentials (77% match rate against a sampled set) to attempt logins against F5 BIG-IP and other edge devices, often routed through a compromised Fortinet firewall; it describes an industrialized supply chain where stolen browser-saved SSO/ADFS credentials are aggregated, sold, and used by initial access brokers to gain network access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
