Infostealers Drive Massive Brute-Force Attacks on Corporate SSO Gateways with Stolen Credentials
Recent cybersecurity analysis reveals an increase in credential-stuffing attacks targeting corporate Single Sign-On (SSO) systems, with F5 BIG-IP devices being a significant focus. Defused Cyber analyzed 70 unique email-password pairs used in these…
Recent cybersecurity analysis reveals an increase in credential-stuffing attacks targeting corporate Single Sign-On (SSO) systems, with F5 BIG-IP devices being a significant focus. Defused Cyber analyzed 70 unique email-password pairs used in these attacks, finding that 77% matched with data from Infostealer infections, showing a connection between data harvested by Infostealers and brute-force attempts on corporate SSO infrastructure.
The stolen credentials were not directly obtained from F5 systems but from compromised employee devices infected with malware like RedLine, Raccoon, or Vidar, which collect browser-saved credentials. These credentials were then used for credential stuffing attacks against corporate portals, relying on password reuse or weak multi-factor authentication (MFA) enforcement.
This campaign illustrates a systematic process where identity theft serves as the primary entry point:
Infection: An employee’s device is infected by an Infostealer, exfiltrating browser-stored credentials. Marketplace: Stolen logs are sold on underground markets to Initial Access Brokers (IABs). Front-Door Bypass: Attackers use these credentials against corporate edge systems like F5 BIG-IP. Network Compromise: Valid credentials allow direct system access.
The attack model emphasizes the importance of identity management over traditional network defenses, exploiting password reuse across systems. Analysis identified compromised credentials from several organizations, indicating widespread targeting across various sectors.
Organization Sector Compromised Domain
Rolls-Royce Aerospace & Defense @ps.rolls-royce.com
Marketplace: Stolen logs are sold on underground markets to Initial Access Brokers (IABs).
Johnson & Johnson Pharmaceuticals @its.jnj.com
Ericsson Telecommunications @ericsson.com
Deloitte Professional Services @deloitte.com
Belgian Police Law Enforcement @police.belgium.eu
Queensland Police Law Enforcement @police.qld.gov.au
Majid Al Futtaim Retail / Conglomerate @maf.ae
Cellebrite Digital Intelligence @cellebrite.com
Doka Engineering @doka.com
Turkish Ministry of Trade Government @ticaret.gov.tr
Attackers employ volume and statistical success, targeting high-value domains expecting some credentials to bypass MFA or cause user fatigue. Security strategies now require continuous identity monitoring and strict MFA enforcement.
Hijacked Infrastructure as Attack Proxies
Further investigation identified the source IP as a compromised Fortinet FortiGate-60E firewall in Japan. The device exposed open ports and used a self-signed SSL certificate, suggesting attackers are using hijacked devices as proxies for their operations. This shows an evolution in cybercriminal tactics, moving from exploiting vulnerabilities to abusing authentication processes.
Based on reporting by GBHackers.
