Close Menu
RoboNewsWire – Latest Insights on AI, Robotics, Crypto and Tech Innovations
  • Home
  • AI
  • Crypto
  • Cybersecurity
  • IT
  • Energy
  • Robotics
  • TechCrunch
  • Technology
What's Hot

Investors trust Google more than Meta when comes to spending on AI

April 30, 2026

Paragon is not collaborating with Italian authorities probing spyware attacks, report says

April 28, 2026

Microsoft cuts OpenAI revenue share as their AI alliance loosens

April 28, 2026
Facebook X (Twitter) Instagram
Trending
  • Investors trust Google more than Meta when comes to spending on AI
  • Paragon is not collaborating with Italian authorities probing spyware attacks, report says
  • Microsoft cuts OpenAI revenue share as their AI alliance loosens
  • Robotically assembled building blocks could make construction more efficient and sustainable | MIT News
  • AI showdown: Musk and Altman go to trial in fight over OpenAI’s beginnings
  • U.S., Iran seize ships as war evolves into standoff over Strait of Hormuz
  • Google launches training and inference TPUs in latest shot at Nvidia
  • Zoom teams up with World to verify humans in meetings
  • Home
  • About Us
  • Advertise
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
RoboNewsWire – Latest Insights on AI, Robotics, Crypto and Tech InnovationsRoboNewsWire – Latest Insights on AI, Robotics, Crypto and Tech Innovations
Thursday, May 7
  • Home
  • AI
  • Crypto
  • Cybersecurity
  • IT
  • Energy
  • Robotics
  • TechCrunch
  • Technology
RoboNewsWire – Latest Insights on AI, Robotics, Crypto and Tech Innovations
Home » Daisy Cloud Hacker Group Exposed 30K Login Credentials Across a Wide Range of Services

Daisy Cloud Hacker Group Exposed 30K Login Credentials Across a Wide Range of Services

GTBy GTMarch 31, 2025 Cybersecurity 2 Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


Daisy Cloud Hacker Group Exposed 30K Login Credentials Across a Wide Range of Services

A significant cybersecurity breach has been uncovered involving the hacker group known as “Daisy Cloud,” which has exposed more than 30,000 login credentials spanning numerous digital services.

Daisy Cloud Hacker Group (Source – Veriti)

The threat actors have been operating a sophisticated credential marketplace on Telegram since October 18, 2023, selling access to financial platforms, cloud services, government portals, and personal accounts at alarmingly accessible prices.

Daisy Cloud marketplace interface (Source – Veriti)

The exposed credentials appear to be harvested through information-stealing malware, potentially linked to the notorious RedLine Stealer family, which has been a persistent threat in the cybercrime ecosystem.

The breach represents an extensive cross-section of digital services, with 25,693 unique websites and applications affected across 108 countries.

The stolen credentials grant access to high-value targets including cryptocurrency exchanges like Binance and Coinbase, personal services such as Facebook and Netflix, and critical infrastructure including government portals from multiple nations.

This diverse targeting strategy demonstrates the threat actor’s intent to maximize monetization opportunities across multiple sectors rather than focusing on a single vertical.

Veriti researchers identified several instances of server-level compromise that showcase the sophisticated nature of the attack.

Analysis of the exposed data dump

During their analysis of the exposed data dump, they discovered administrative access to cloud and on-premise servers spanning multiple geographic regions.

Exposed data dump (Source – Veriti)

The researchers noted that many of these servers lacked proper security controls, with some missing antivirus protection entirely, creating an ideal environment for malware propagation and persistence.

The server-level exposure represents perhaps the most concerning aspect of this breach.

In one documented case, a server in Southeast Asia, likely belonging to an educational institution, was compromised with full administrative privileges.

The configuration suggested it was used for development purposes, making it a potential staging ground for deeper network penetration.

Without the appropriate endpoint protection mechanisms, the server remained vulnerable to a range of attack vectors.

// Simplified infection chain pseudocode
function infectionChain() {
initialAccess = deployPhishingCampaign();
if (initialAccess) {
stageOnePayload = downloadInfostealer();
harvestedCredentials = stageOnePayload.execute();
uploadToC2Server(harvestedCredentials);
if (detectsHighValueTarget()) {
deployLateralMovementTools();
compromiseAdditionalSystems();
}
}
}

The Daisy Cloud incident demonstrates the evolution of credential theft operations from opportunistic attacks to sophisticated, multi-stage campaigns with potential for lateral movement.

Veriti researchers observed evidence of coordinated infections across entire network segments in several countries, including Poland, the Netherlands, the UK, and the United States.

This suggests that initial credential theft serves as merely the first stage in a broader access operation potentially leading to ransomware deployment or data exfiltration.

Are You from SOC/DFIR Team? – Try Free Malware Research with ANY.RUN – Start Now



Source link

GT
  • Website

Keep Reading

Malicious Chrome Extension Steal ChatGPT and DeepSeek Conversations from 900K Users

Top 10 Best Server Monitoring Tools

10 Best Cybersecurity Risk Management Tools

Best DDoS Protection Tools & Services in 2026 (Reviewed)

20 Best Malware Protection Solutions In 2026

10 Most Notable Cyber Attacks of 2026

View 2 Comments

2 Comments

  1. 📝 Message: Process 1,633257 BTC. Withdraw => https://graph.org/Message--04804-03-25?hs=e53afe214af29c9b677a62790e00f74e& 📝 on April 14, 2025 8:10 am

    39ywp0

    Reply
  2. 📂 + 1.802989 BTC.NEXT - https://graph.org/Message--685-03-25?hs=e53afe214af29c9b677a62790e00f74e& 📂 on April 15, 2025 9:25 pm

    33m8yo

    Reply
Leave A Reply Cancel Reply

Editors Picks

Investors trust Google more than Meta when comes to spending on AI

April 30, 2026

Google launches training and inference TPUs in latest shot at Nvidia

April 27, 2026

Meta tracks employee usage on Google, LinkedIn AI training project

April 25, 2026

Meta will cut 10% of workforce as company pushes deeper into AI

April 24, 2026
Latest Posts

Malicious Chrome Extension Steal ChatGPT and DeepSeek Conversations from 900K Users

April 1, 2026

Top 10 Best Server Monitoring Tools

April 1, 2026

10 Best Cybersecurity Risk Management Tools

March 31, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Welcome to RoboNewsWire, your trusted source for cutting-edge news and insights in the world of technology. We are dedicated to providing timely and accurate information on the most important trends shaping the future across multiple sectors. Our mission is to keep you informed and ahead of the curve with deep dives, expert analysis, and the latest updates in key industries that are transforming the world.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2026 Robonewswire. Designed by robonewswire.

Type above and press Enter to search. Press Esc to cancel.