HomeData BreachHackers Utilizing E-Crime Software Atlantis AIO for Credential Stuffing on 140+ Platforms

Hackers Utilizing E-Crime Software Atlantis AIO for Credential Stuffing on 140+ Platforms

Menace actors are leveraging an e-crime device known as Atlantis AIO Multi-Checker to automate credential stuffing assaults, based on findings from Irregular Safety.

Atlantis AIO “has emerged as a strong weapon within the cybercriminal arsenal, enabling attackers to check thousands and thousands of stolen credentials in speedy succession,” the cybersecurity firm stated in an evaluation.

Credential stuffing is a sort of cyber assault wherein an adversary collects stolen account credentials, sometimes consisting of lists of usernames or e mail addresses and passwords, after which makes use of them to realize unauthorized entry to consumer accounts on unrelated methods by means of large-scale automated login requests.

Cybersecurity

Such credentials could possibly be obtained from a data breach of a social media service or be acquired from underground boards the place they’re marketed on the market by different risk actors.

Credential stuffing can also be completely different from brute-force assaults, which revolve round cracking passwords, login credentials, and encryption keys utilizing a trial and error methodology.

See also  5 Actionable Steps to Stop GenAI Data Leaks With out Totally Blocking AI Utilization

Atlantis AIO, per Irregular Safety, affords risk actors the power to launch credential stuffing assaults at scale through pre-configured modules for focusing on a spread of platforms and cloud-based companies, thereby facilitating fraud, knowledge theft, and account takeovers.

“Atlantis AIO Multi-Checker is a cybercriminal device designed to automate credential stuffing assaults,” it stated. “Able to testing stolen credentials at scale, it could possibly shortly try thousands and thousands of username and password combos throughout greater than 140 platforms.”

E-Crime Tool Atlantis AIO

The risk actors behind this system additionally declare that it is constructed on “a basis of confirmed success” and that they’ve 1000’s of glad purchasers, whereas assuring clients of the security ensures baked into the platform with a view to maintain their buy personal.

“Each function, replace, and interplay is crafted with meticulous consideration to raise your expertise past expectations,” they state within the official commercial, including “we frequently pioneer options that drive unprecedented outcomes.”

See also  Change Healthcare hacked utilizing stolen Citrix account with no MFA

Targets of Atlantis AIO embody e mail suppliers like Hotmail, Yahoo, AOL, GMX, and Internet.de, in addition to e-commerce, streaming companies, VPNs, monetary establishments, and meals supply companies.

Cybersecurity

One other notable side of the device is its capability to conduct brute-force assaults towards the aforementioned e mail platforms and automate account restoration processes related to eBay and Yahoo.

“Credential stuffing instruments like Atlantis AIO present cybercriminals with a direct path to monetizing stolen credentials,” Irregular Safety stated.

“As soon as they acquire entry to accounts throughout numerous platforms, attackers can exploit them in a number of methods — e.g., promoting login particulars on darkish internet marketplaces, committing fraud, or utilizing compromised accounts to distribute spam and launch phishing campaigns.”

To mitigate the account takeover dangers posed by such assaults, it is advisable to enact strict password guidelines and implement phishing-resistant multi-factor authentication (MFA) mechanisms.

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular