logo

Hackers steal 15,000 cloud credentials from exposed Git config files

ID: 120bd8a5-b447-5f60-9f41-5c0df249f4da

STIX ID: report--120bd8a5-b447-5f60-9f41-5c0df249f4da

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

EmeraldWhale is a large criminal campaign that scanned millions of IPs for exposed .git and .env files to harvest authentication tokens, validated and used them to download private repositories, and exfiltrated roughly 15,000 cloud credentials to victim S3 buckets; the stolen secrets were used in phishing/spam campaigns and sold to other criminals, leveraging commodity tools like Masscan, httpx, Multigrabber, Mizaru, and Seyzo.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.