Wide Open Botnet Attackers Leave Credential Stuffing Network Vulnerable via Full Admin Leaks
ID: 4ddf5a46-aca2-5782-8e32-5f5f14ae4a24
STIX ID: report--4ddf5a46-aca2-5782-8e32-5f5f14ae4a24
Feed Name: Cyber Press
An unauthenticated Flask-based command-and-control panel called "Twitter Checker Master Panel – FULL FIX v2.3" was publicly accessible (144.76.57.92:5000), exposing worker servers, plaintext root SSH credentials, live attack controls, and result files for a credential-stuffing campaign against Twitter/X. Observers recorded 722,763 credential tests and 18 compromises in a 12-minute window and lifetime statistics of ~4.8 million tests and 138 confirmed compromises; two-factor authentication prevented most successful takeovers. The Turkish-language interface and infrastructure in Ankara suggest a Turkish-speaking operator, and the exposure provides actionable intelligence for defenders to block infrastructure and assist takedown efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
