logo

Wide Open Botnet Attackers Leave Credential Stuffing Network Vulnerable via Full Admin Leaks

ID: 4ddf5a46-aca2-5782-8e32-5f5f14ae4a24

STIX ID: report--4ddf5a46-aca2-5782-8e32-5f5f14ae4a24

Feed Name: Cyber Press

Threat Score
60/100

Date Published: 2026-04-14

Date Updated: 2026-04-19

Author: Varshini

...
...

An unauthenticated Flask-based command-and-control panel called "Twitter Checker Master Panel – FULL FIX v2.3" was publicly accessible (144.76.57.92:5000), exposing worker servers, plaintext root SSH credentials, live attack controls, and result files for a credential-stuffing campaign against Twitter/X. Observers recorded 722,763 credential tests and 18 compromises in a 12-minute window and lifetime statistics of ~4.8 million tests and 138 confirmed compromises; two-factor authentication prevented most successful takeovers. The Turkish-language interface and infrastructure in Ankara suggest a Turkish-speaking operator, and the exposure provides actionable intelligence for defenders to block infrastructure and assist takedown efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.