{"id":9665,"date":"2026-01-06T10:04:35","date_gmt":"2026-01-06T10:04:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/06\/threat-actors-hacked-global-companies-via-leaked-cloud-credentials-from-infostealer-infections\/"},"modified":"2026-01-06T10:04:35","modified_gmt":"2026-01-06T10:04:35","slug":"threat-actors-hacked-global-companies-via-leaked-cloud-credentials-from-infostealer-infections","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/06\/threat-actors-hacked-global-companies-via-leaked-cloud-credentials-from-infostealer-infections\/","title":{"rendered":"Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections"},"content":{"rendered":"<p>    Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Dozens of major global enterprises have been breached through a surprisingly simple yet devastating attack vector: stolen credentials extracted from infostealer malware. <\/p>\n<p>A threat actor operating under the nickname \u201cZestix\u201d and his alias \u201cSentap\u201d has been systematically accessing corporate cloud storage platforms, including ShareFile, Nextcloud, and OwnCloud, belonging to approximately 50 international organizations. <\/p>\n<p>The breaches span critical sectors such as aviation, defense robotics, healthcare, finance, and government infrastructure, exposing terabytes of sensitive data.<\/p>\n<p>The attack chain reveals a troubling reality in modern cybersecurity. Employees inadvertently download malicious files that execute infostealers like RedLine, <a href=\"https:\/\/cybersecuritynews.com\/lumma-infostealers-developers-trying-hard\/\" target=\"_blank\" rel=\"noreferrer noopener\">Lumma<\/a>, and Vidar. <\/p>\n<p>These malware variants silently harvest all saved credentials and browser history from infected devices. Once extracted, these logs are aggregated into massive databases on the dark web. <\/p>\n<p>Zestix then searches through these repositories specifically looking for corporate cloud URLs and uses the stolen credentials to gain unauthorized access to enterprise systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjrM3JYGTDd_Kf-eGSDmmIiEyjy6H_o1kVnaAUL4LwqXQh2K7TzeJKqQ5EXZo90noD6xdRkS7EarIPUl9P3XJL3mwW18wAklNCEINZbi4FrbUxBdfLoPpNDehEuph31dwDzRYVSZaG_hBKY0HEA_iQiFm8bav4wSycoJZu3uFsIaWyXh22l2RV5ekAFGdE\/s16000\/The%2520digital%2520persona%2520of%2520%27Zestix%2C%27%2520a%2520threat%2520actor%2520specializing%2520in%2520auctioning%2520corporate%2520cloud%2520access%2520%28Source%2520-%2520Infostealers%29.webp?ssl=1\" alt=\"The digital persona of 'Zestix,' a threat actor specializing in auctioning corporate cloud access (Source - Infostealers)\"><figcaption class=\"wp-element-caption\">The digital persona of \u2018Zestix,\u2019 a threat actor specializing in auctioning corporate cloud access (Source \u2013 Infostealers)<\/figcaption><\/figure>\n<\/div>\n<p>InfoStealers analysts and researchers <a href=\"https:\/\/www.infostealers.com\/article\/dozens-of-global-companies-hacked-via-cloud-credentials-from-infostealer-infections-more-at-risk\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the most critical vulnerability enabling these breaches was not a sophisticated zero-day exploit, but rather the fundamental absence of Multi-Factor Authentication (MFA). <\/p>\n<p>Organizations failed to implement this standard security control, allowing attackers to walk through the front door using only a valid username and password. <\/p>\n<p>Some credentials had been sitting in infostealer logs for years, creating a window of opportunity that organizations completely missed.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi3ku-9mLzv7rbqlTuMFVAlDT_XMjj2IdEZQ1uk9RfJVssc0hzcPMC9hCb8bdEVvnY9-d289_yAiNb0t5Yn8QaJQcxfUWHUJiE0Bsa2E1-5TaTHw65DvOc-ZmLlhwsAxJKHc5D2VjSGIIBLrNn2MsVGf_mPXM_tV_smxRvtcBYGgL8f-3imbYeeCU1VE3I\/s16000\/The%2520%27Sentap%27%2520profile%2C%2520an%2520alias%2520used%2520by%2520Zestix%2520to%2520sell%2520additional%2520compromised%2520datasets%2520%28Source%2520-%2520Infostealers%29.webp?ssl=1\" alt=\"The 'Sentap' profile, an alias used by Zestix to sell additional compromised datasets (Source - Infostealers)\"><figcaption class=\"wp-element-caption\">The \u2018Sentap\u2019 profile, an alias used by Zestix to sell additional compromised datasets (Source \u2013 Infostealers)<\/figcaption><\/figure>\n<\/div>\n<p>The scale of the compromises is alarming. Pickett and Associates, an engineering firm serving U.S. utility companies, lost 139.1 gigabytes including classified LiDAR files and transmission line maps. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi3mdhhywUZF7GSOvfwzSMC9vS__ApQextXLBRweaP0IvReyePU0VgFnmjtvPBVw-clvXrQBd9PxD6L3MUmtfRGkpEORhzYEUFRBTjA0KZX9nhHK9GqRAaWD0wxlxwjM-KhYl5TLC3Xr6zowzkwtTeK1fvTlREAjxUkVryDF8sFgaqEaV7D7UWz3qBv__U\/s16000\/The%2520Pickett%2520%26%2520Associates%2520portal%2C%2520accessed%2520via%2520stolen%2520credentials%2520%28Source%2520-%2520Infostealers%29.webp?ssl=1\" alt=\"The Pickett &amp; Associates portal, accessed via stolen credentials (Source - Infostealers)\"><figcaption class=\"wp-element-caption\">The Pickett &amp; Associates portal, accessed via stolen credentials (Source \u2013 Infostealers)<\/figcaption><\/figure>\n<\/div>\n<p>Intecro Robotics exposed 11.5 gigabytes of ITAR-controlled defense blueprints for military aircraft components. Iberia Airlines had 77 gigabytes leaked, containing aircraft maintenance programs and critical flight safety documentation. <\/p>\n<p>Brazilian military police health records belonging to Maida Health\u20142.3 terabytes in total\u2014were exposed, along with personal identification and medical information for active-duty personnel and their families.<\/p>\n<h2 class=\"wp-block-heading\" id=\"deep-analysis-the-credential-harvesting-mechanism\"><strong>The Credential Harvesting Mechanism<\/strong><\/h2>\n<p>The infection cycle operates through a five-stage process that cybersecurity professionals must understand. First, an employee receives a seemingly legitimate file through email or downloads what appears to be standard software. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgqaym9-RtlWsOhgT5J4yE69yG8QrPPW72ZLjtpeX2eMazbBZXJUppRb1_6elZ2C-zR5tkBmJIKZmgiEruXdGNL2GpxLi3NDEMG0R1gGzfxJ4fz7E-rkHRfiARCWV8_Li5vhwG93m4h5HDcUFIcSMTFm934fKblszf-rEL0piP5os1Kn5yhrLreqGSZ-0\/s16000\/Stolen%2520blueprints%2520for%2520defense%2520robotics%2520components%2520%28Source%2520-%2520Infostealers%29.webp?ssl=1\" alt=\"Stolen blueprints for defense robotics components (Source - Infostealers)\"><figcaption class=\"wp-element-caption\">Stolen blueprints for defense robotics components (Source \u2013 Infostealers)<\/figcaption><\/figure>\n<\/div>\n<p>Second, the <a href=\"https:\/\/cybersecuritynews.com\/rhadamanthys-infostealer-leveraging-clickfix\/\" target=\"_blank\" rel=\"noreferrer noopener\">infostealer<\/a> executes in memory, often avoiding detection by security tools because it operates within legitimate processes. Third, the malware enumerates browser storage, password managers, and cached credentials from applications like Outlook and Teams. <\/p>\n<p>Fourth, all harvested data is encrypted and transmitted to <a href=\"https:\/\/cybersecuritynews.com\/pcpcat-hacked-next-js-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">command-and-control servers<\/a>. Finally, threat actors parse through thousands of stolen credential databases, filtering specifically for corporate infrastructure like cloud file shares and ERP systems.<\/p>\n<p>What makes this approach particularly dangerous is its scale and low cost. Zestix operates as an Initial Access Broker, selling corporate access credentials for Bitcoin or Monero on underground forums. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiLamZ22T63HqK9S7MZ3vL-MmtWVONg6wwEFgut2BOk7jb1p4EToU8W6OJV90xtzVjQ-jQKXwWLfjvcNBLX-EOXl4_ou59MkT6Gu5_UJ8hJe635mm4zgY7OKZPM3MDb4IR5FiKNZp8M6IPcoXNDcqmL-gMgxDIE7vq1BhF0VAmH9N_thza64nfpCVjkJXY\/s16000\/Exposed%2520legal%2520and%2520financial%2520directories%2520%28Source%2520-%2520Infostealers%29.webp?ssl=1\" alt=\"Exposed legal and financial directories (Source - Infostealers)\"><figcaption class=\"wp-element-caption\">Exposed legal and financial directories (Source \u2013 Infostealers)<\/figcaption><\/figure>\n<\/div>\n<p>Organizations have failed not because they lack <a href=\"https:\/\/cybersecuritynews.com\/security-awareness-in-2025-why-awareness-is-more-important-than-ever\/\" target=\"_blank\" rel=\"noreferrer noopener\">security awareness<\/a> programs, but because they have not enforced mandatory multi-factor authentication across all critical systems. <\/p>\n<p>The remedy is straightforward: immediate MFA deployment combined with monitoring for compromised credentials in infostealer logs before attackers exploit them.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-hacked-global-companies-via-leaked-cloud-credentials\/\">Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-hacked-global-companies-via-leaked-cloud-credentials\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections Dozens of major global enterprises have been breached through a surprisingly simple yet devastating attack vector: stolen credentials extracted from infostealer malware. A threat actor operating under the nickname \u201cZestix\u201d and his alias \u201cSentap\u201d has been systematically accessing corporate cloud storage platforms, including [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9665","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9665"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9665"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9665\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}