Hackers steal 15,000 cloud credentials from exposed Git config files
ID: 120bd8a5-b447-5f60-9f41-5c0df249f4da
STIX ID: report--120bd8a5-b447-5f60-9f41-5c0df249f4da
Feed Name: Bleeping Computer
Threat Score
EmeraldWhale is a large criminal campaign that scanned millions of IPs for exposed .git and .env files to harvest authentication tokens, validated and used them to download private repositories, and exfiltrated roughly 15,000 cloud credentials to victim S3 buckets; the stolen secrets were used in phishing/spam campaigns and sold to other criminals, leveraging commodity tools like Masscan, httpx, Multigrabber, Mizaru, and Seyzo.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
