EMERALDWHALE Attacks Targeting Exposed Git Config Files (Campaign)
ID: c51c5084-3b31-5be9-86a0-08a1c8e394a6
STIX ID: report--c51c5084-3b31-5be9-86a0-08a1c8e394a6
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-30
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Research uncovered the EMERALDWHALE campaign that abused exposed `.git/config` and Laravel `.env` files to exfiltrate sensitive credentials from private repositories and cloud environments; attackers used automated scanning and extraction tools (MZR V2/MIZARU, Seyzo-v2, git-dumper, httpx), collected over a terabyte of data including more than 15,000 cloud credentials, and stored the results in a publicly accessible S3 bucket to enable phishing, spam, and further misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
