logo

'Crystalray' Attacks Jump 10X, Using Only OSS to Steal Credentials

ID: 8e3cb154-426b-5998-bb58-a69b9e58c6fc

STIX ID: report--8e3cb154-426b-5998-bb58-a69b9e58c6fc

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-07-11

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Crystalray is a recently observed threat actor using open-source security and offensive tools (ASN, zmap, httpx, nuclei, SSH‑Snake, Sliver, Platypus) and public PoCs to exploit critical vulnerabilities (including Confluence and several CVEs) to drop credential-stealing tools and cryptominers; researchers observed activity affecting roughly 1,800 unique IPs worldwide with hundreds of active infections, monetizing stolen credentials and modest crypto-mining proceeds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.