'Crystalray' Attacks Jump 10X, Using Only OSS to Steal Credentials
ID: 8e3cb154-426b-5998-bb58-a69b9e58c6fc
STIX ID: report--8e3cb154-426b-5998-bb58-a69b9e58c6fc
Feed Name: Dark Reading
Threat Score
Crystalray is a recently observed threat actor using open-source security and offensive tools (ASN, zmap, httpx, nuclei, SSH‑Snake, Sliver, Platypus) and public PoCs to exploit critical vulnerabilities (including Confluence and several CVEs) to drop credential-stealing tools and cryptominers; researchers observed activity affecting roughly 1,800 unique IPs worldwide with hundreds of active infections, monetizing stolen credentials and modest crypto-mining proceeds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
