Cyber Security News

Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections

Dozens of major global enterprises have been breached through a surprisingly simple yet devastating attack vector: stolen credentials extracted from infostealer malware.

A threat actor operating under the nickname “Zestix” and his alias “Sentap” has been systematically accessing corporate cloud storage platforms, including ShareFile, Nextcloud, and OwnCloud, belonging to approximately 50 international organizations.

The breaches span critical sectors such as aviation, defense robotics, healthcare, finance, and government infrastructure, exposing terabytes of sensitive data.

The attack chain reveals a troubling reality in modern cybersecurity. Employees inadvertently download malicious files that execute infostealers like RedLine, Lumma, and Vidar.

These malware variants silently harvest all saved credentials and browser history from infected devices. Once extracted, these logs are aggregated into massive databases on the dark web.

Zestix then searches through these repositories specifically looking for corporate cloud URLs and uses the stolen credentials to gain unauthorized access to enterprise systems.

The digital persona of ‘Zestix,’ a threat actor specializing in auctioning corporate cloud access (Source – Infostealers)

InfoStealers analysts and researchers noted that the most critical vulnerability enabling these breaches was not a sophisticated zero-day exploit, but rather the fundamental absence of Multi-Factor Authentication (MFA).

Organizations failed to implement this standard security control, allowing attackers to walk through the front door using only a valid username and password.

Some credentials had been sitting in infostealer logs for years, creating a window of opportunity that organizations completely missed.

The ‘Sentap’ profile, an alias used by Zestix to sell additional compromised datasets (Source – Infostealers)

The scale of the compromises is alarming. Pickett and Associates, an engineering firm serving U.S. utility companies, lost 139.1 gigabytes including classified LiDAR files and transmission line maps.

The Pickett & Associates portal, accessed via stolen credentials (Source – Infostealers)

Intecro Robotics exposed 11.5 gigabytes of ITAR-controlled defense blueprints for military aircraft components. Iberia Airlines had 77 gigabytes leaked, containing aircraft maintenance programs and critical flight safety documentation.

Brazilian military police health records belonging to Maida Health—2.3 terabytes in total—were exposed, along with personal identification and medical information for active-duty personnel and their families.

The Credential Harvesting Mechanism

The infection cycle operates through a five-stage process that cybersecurity professionals must understand. First, an employee receives a seemingly legitimate file through email or downloads what appears to be standard software.

Stolen blueprints for defense robotics components (Source – Infostealers)

Second, the infostealer executes in memory, often avoiding detection by security tools because it operates within legitimate processes. Third, the malware enumerates browser storage, password managers, and cached credentials from applications like Outlook and Teams.

Fourth, all harvested data is encrypted and transmitted to command-and-control servers. Finally, threat actors parse through thousands of stolen credential databases, filtering specifically for corporate infrastructure like cloud file shares and ERP systems.

What makes this approach particularly dangerous is its scale and low cost. Zestix operates as an Initial Access Broker, selling corporate access credentials for Bitcoin or Monero on underground forums.

Exposed legal and financial directories (Source – Infostealers)

Organizations have failed not because they lack security awareness programs, but because they have not enforced mandatory multi-factor authentication across all critical systems.

The remedy is straightforward: immediate MFA deployment combined with monitoring for compromised credentials in infostealer logs before attackers exploit them.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

7 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

12 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

17 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

23 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

34 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago