logo

Infostealers Drive Massive Brute-Force Attacks on Corporate SSO Gateways with Stolen Credentials

ID: 9ed55193-17c0-5f7d-9f5e-a4ce6edcf0c7

STIX ID: report--9ed55193-17c0-5f7d-9f5e-a4ce6edcf0c7

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-02-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report details an active credential‑stuffing campaign that repurposes credentials exfiltrated by Infostealer families (RedLine, Raccoon, Vidar) to target corporate SSO gateways (F5 BIG‑IP, ADFS, OWA). Analysis found 77% of a 70‑credential sample matched Infostealer logs, attackers used hijacked edge devices as proxies, and multiple high‑value organizations had exposed domains in the payloads—underscoring large‑scale identity‑based access abuse and the need for continuous identity monitoring and strict MFA enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.