Infostealers Drive Massive Brute-Force Attacks on Corporate SSO Gateways with Stolen Credentials
ID: 9ed55193-17c0-5f7d-9f5e-a4ce6edcf0c7
STIX ID: report--9ed55193-17c0-5f7d-9f5e-a4ce6edcf0c7
Feed Name: GBHackers
This report details an active credential‑stuffing campaign that repurposes credentials exfiltrated by Infostealer families (RedLine, Raccoon, Vidar) to target corporate SSO gateways (F5 BIG‑IP, ADFS, OWA). Analysis found 77% of a 70‑credential sample matched Infostealer logs, attackers used hijacked edge devices as proxies, and multiple high‑value organizations had exposed domains in the payloads—underscoring large‑scale identity‑based access abuse and the need for continuous identity monitoring and strict MFA enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
