14 C
United States of America
Saturday, March 29, 2025

Hackers Utilizing E-Crime Instrument Atlantis AIO for Credential Stuffing on 140+ Platforms


Mar 26, 2025Ravie LakshmananPassword Safety / Cybercrime

Hackers Utilizing E-Crime Instrument Atlantis AIO for Credential Stuffing on 140+ Platforms

Risk actors are leveraging an e-crime instrument known as Atlantis AIO Multi-Checker to automate credential stuffing assaults, in response to findings from Irregular Safety.

Atlantis AIO “has emerged as a strong weapon within the cybercriminal arsenal, enabling attackers to check hundreds of thousands of stolen credentials in fast succession,” the cybersecurity firm mentioned in an evaluation.

Credential stuffing is a sort of cyber assault through which an adversary collects stolen account credentials, sometimes consisting of lists of usernames or electronic mail addresses and passwords, after which makes use of them to achieve unauthorized entry to consumer accounts on unrelated programs by means of large-scale automated login requests.

Cybersecurity

Such credentials may very well be obtained from a knowledge breach of a social media service or be acquired from underground boards the place they’re marketed on the market by different menace actors.

Credential stuffing can also be totally different from brute-force assaults, which revolve round cracking passwords, login credentials, and encryption keys utilizing a trial and error technique.

Atlantis AIO, per Irregular Safety, affords menace actors the flexibility to launch credential stuffing assaults at scale by way of pre-configured modules for focusing on a spread of platforms and cloud-based providers, thereby facilitating fraud, information theft, and account takeovers.

“Atlantis AIO Multi-Checker is a cybercriminal instrument designed to automate credential stuffing assaults,” it mentioned. “Able to testing stolen credentials at scale, it may well shortly try hundreds of thousands of username and password mixtures throughout greater than 140 platforms.”

E-Crime Tool Atlantis AIO

The menace actors behind this system additionally declare that it is constructed on “a basis of confirmed success” and that they’ve 1000’s of glad shoppers, whereas assuring clients of the safety ensures baked into the platform so as to preserve their buy personal.

“Each function, replace, and interplay is crafted with meticulous consideration to raise your expertise past expectations,” they state within the official commercial, including “we frequently pioneer options that drive unprecedented outcomes.”

Targets of Atlantis AIO embody electronic mail suppliers like Hotmail, Yahoo, AOL, GMX, and Internet.de, in addition to e-commerce, streaming providers, VPNs, monetary establishments, and meals supply providers.

Cybersecurity

One other notable side of the instrument is its capability to conduct brute-force assaults in opposition to the aforementioned electronic mail platforms and automate account restoration processes related to eBay and Yahoo.

“Credential stuffing instruments like Atlantis AIO present cybercriminals with a direct path to monetizing stolen credentials,” Irregular Safety mentioned.

“As soon as they acquire entry to accounts throughout varied platforms, attackers can exploit them in a number of methods — e.g., promoting login particulars on darkish internet marketplaces, committing fraud, or utilizing compromised accounts to distribute spam and launch phishing campaigns.”

To mitigate the account takeover dangers posed by such assaults, it is beneficial to enact strict password guidelines and implement phishing-resistant multi-factor authentication (MFA) mechanisms.

Discovered this text attention-grabbing? Observe us on Twitter and LinkedIn to learn extra unique content material we submit.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles