21 C
New York
Sunday, March 30, 2025

Hackers Utilizing E-Crime Device Atlantis AIO for Credential Stuffing on 140+ Platforms


Mar 26, 2025Ravie LakshmananPassword Safety / Cybercrime

Hackers Utilizing E-Crime Device Atlantis AIO for Credential Stuffing on 140+ Platforms

Risk actors are leveraging an e-crime software referred to as Atlantis AIO Multi-Checker to automate credential stuffing assaults, in keeping with findings from Irregular Safety.

Atlantis AIO “has emerged as a robust weapon within the cybercriminal arsenal, enabling attackers to check tens of millions of stolen credentials in fast succession,” the cybersecurity firm mentioned in an evaluation.

Credential stuffing is a kind of cyber assault during which an adversary collects stolen account credentials, usually consisting of lists of usernames or e mail addresses and passwords, after which makes use of them to realize unauthorized entry to person accounts on unrelated programs via large-scale automated login requests.

Cybersecurity

Such credentials may very well be obtained from a knowledge breach of a social media service or be acquired from underground boards the place they’re marketed on the market by different menace actors.

Credential stuffing can also be completely different from brute-force assaults, which revolve round cracking passwords, login credentials, and encryption keys utilizing a trial and error methodology.

Atlantis AIO, per Irregular Safety, gives menace actors the power to launch credential stuffing assaults at scale through pre-configured modules for concentrating on a spread of platforms and cloud-based providers, thereby facilitating fraud, knowledge theft, and account takeovers.

“Atlantis AIO Multi-Checker is a cybercriminal software designed to automate credential stuffing assaults,” it mentioned. “Able to testing stolen credentials at scale, it may rapidly try tens of millions of username and password combos throughout greater than 140 platforms.”

E-Crime Tool Atlantis AIO

The menace actors behind this system additionally declare that it is constructed on “a basis of confirmed success” and that they’ve 1000’s of happy purchasers, whereas assuring clients of the safety ensures baked into the platform in an effort to preserve their buy non-public.

“Each characteristic, replace, and interplay is crafted with meticulous consideration to raise your expertise past expectations,” they state within the official commercial, including “we frequently pioneer options that drive unprecedented outcomes.”

Targets of Atlantis AIO embrace e mail suppliers like Hotmail, Yahoo, AOL, GMX, and Net.de, in addition to e-commerce, streaming providers, VPNs, monetary establishments, and meals supply providers.

Cybersecurity

One other notable side of the software is its potential to conduct brute-force assaults in opposition to the aforementioned e mail platforms and automate account restoration processes related to eBay and Yahoo.

“Credential stuffing instruments like Atlantis AIO present cybercriminals with a direct path to monetizing stolen credentials,” Irregular Safety mentioned.

“As soon as they achieve entry to accounts throughout varied platforms, attackers can exploit them in a number of methods — e.g., promoting login particulars on darkish internet marketplaces, committing fraud, or utilizing compromised accounts to distribute spam and launch phishing campaigns.”

To mitigate the account takeover dangers posed by such assaults, it is advisable to enact strict password guidelines and implement phishing-resistant multi-factor authentication (MFA) mechanisms.

Discovered this text attention-grabbing? Comply with us on Twitter and LinkedIn to learn extra unique content material we put up.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles