logo

How Infostealers Industrialize the Brute-Forcing of Corporate SSO Gateways

ID: a08a5205-4130-5e36-8ab6-71710b5174ed

STIX ID: report--a08a5205-4130-5e36-8ab6-71710b5174ed

Feed Name: infostealers.com

Threat Score
75/100

Date Published: 2026-02-26

Date Updated: 2026-04-28

Author: InfoStealers

...
...

This report details a credential-stuffing campaign that leveraged Infostealer-harvested credentials (77% match rate against a sampled set) to attempt logins against F5 BIG-IP and other edge devices, often routed through a compromised Fortinet firewall; it describes an industrialized supply chain where stolen browser-saved SSO/ADFS credentials are aggregated, sold, and used by initial access brokers to gain network access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.