Infostealers Fuel Large‑Scale Brute‑Forcing of Corporate SSO Gateways Using Stolen Credentials
Recent cyberattacks have highlighted a shift in methodologies used by threat actors, particularly focusing on credential stuffing rather than exploiting software vulnerabilities. These attacks leverage stolen passwords to gain unauthorized access to…
Recent cyberattacks have highlighted a shift in methodologies used by threat actors, particularly focusing on credential stuffing rather than exploiting software vulnerabilities. These attacks leverage stolen passwords to gain unauthorized access to corporate networks.
Infostealer Malware and Brute-Force Attacks
Infostealer malware families are central to this new wave of attacks. They harvest credentials from infected employee devices, which are then used in brute-force attacks against corporate Single Sign-On (SSO) gateways, with a specific focus on F5 BIG-IP interfaces.
On February 23, 2026, a significant credential stuffing campaign targeting F5 devices was identified by threat intelligence group Defused Cyber. This campaign involved POST requests from a source IP linked to OPTAGE Inc. in Japan, using large-scale corporate email and password combinations.
The campaign was noted for its precision, utilizing real, functional logins associated with multinational companies and government agencies. Analysts traced these credentials back to infostealer infections using Hudson Rock’s cybercrime database.
Out of 70 email-password combinations observed, 54 matched known infostealer infection logs, indicating a 77% match rate. These credentials were not from a traditional data breach but were instead harvested from infected devices and used against external infrastructures like ADFS, STS, and OWA portals.
These attacks leverage stolen passwords to gain unauthorized access to corporate networks.
Affected organizations include Rolls-Royce, Johnson & Johnson, Ericsson, Deloitte, Cellebrite, and various police departments. The attack also targeted government and large retail conglomerates, emphasizing the need for multi-factor authentication to prevent unauthorized access.
The source IP was linked to a compromised Fortinet FortiGate-60E firewall, showing attackers routing traffic through hijacked edge devices. This dual-threat approach combines stolen identities with compromised network infrastructure, complicating detection efforts.
The technical process involved in these attacks is described as a "Log-to-Lead" pipeline, converting infostealer infection data into network access. The malware extracts browser-saved credentials, which are sold on dark web marketplaces to Initial Access Brokers.
Attackers use these credentials to access corporate edge devices, exploiting functional equivalence where master credentials are accepted across various access points like VPNs and SSO portals.
To counter these threats, organizations should enforce phishing-resistant MFA across all systems and monitor exposed credentials through cybercrime intelligence feeds. Internal password reuse must be eliminated, and endpoint security should intercept infostealer infections before credentials reach the dark web.
Employee training on the risks of browser-saved passwords is also crucial, as these habits contribute to the infostealer pipeline.
Based on reporting by Cyber Security News.
