Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-access-methodphishing-campaign-intelligencedefense-evasion-methodcredential-stealer-activity

Credential Theft and Evasion Techniques Across Phishing, Webmail Exploitation, and Commodity Malware

Updated 3mo agoFirst seen Mar 12, 20265 sources

Threat actors are continuing to prioritize credential theft while using defensive and trusted services to evade detection. DomainTools reported a Microsoft 365 phishing operation that weaponizes Cloudflare protections (including Turnstile human verification) to block automated analysis and security crawlers, then selectively serves a credential-harvesting flow only to “clean” visitors. The infrastructure used additional gatekeeping such as IP reputation checks (including lookups via api.ipify.org), hardcoded blocks for security-vendor and cloud-provider ranges, and user-agent filtering that returns a fake 404 page to bots, with the theft logic hidden behind heavy obfuscation.

Separately, Hunt.io documented Operation Roundish, assessed with medium-high confidence as aligned to APT28 (Fancy Bear), after discovering an exposed open directory hosting a Roundcube exploitation toolkit used against Ukrainian targets (including mail.dmsu.gov.ua). The toolkit included XSS payloads, a Flask-based C2, and modules for credential harvesting, mail forwarding persistence, bulk email exfiltration, address book theft, and 2FA secret extraction, plus a Go-based Linux implant (httd) found on a compromised Ukrainian web application. In parallel reporting on credential-access tradecraft, Flashpoint analysis highlighted the low-cost DarkCloud infostealer (sold for about $30) that steals browser logins/cookies and other data and exfiltrates via common channels (email/FTP/Telegram/HTTP), while Aryaka Threat Labs described the BlackSanta campaign using steganographic lures and BYOVD techniques to disable EDR and enable stealthy data theft over HTTPS—underscoring that credential access and defense evasion remain common precursors to broader enterprise compromise.

Share:
Credential Theft and Evasion Techniques Across Phishing, Webmail Exploitation, and Commodity Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 24, 20263mo ago

Phishing campaign targets TikTok for Business accounts

Push Security reported a phishing campaign targeting TikTok for Business users with Cloudflare-hosted pages, Google Storage redirects, and Cloudflare Turnstile checks to evade analysis. The operation uses reverse-proxy phishing pages to steal credentials and session cookies, enabling account hijacking even when two-factor authentication is enabled, with attacker domains registered on 2026-03-24.

TikTok for Business accounts targeted in new phishing campaign
Mar 12, 20263mo ago

DomainTools identifies Cloudflare-assisted Microsoft 365 phishing campaign

DomainTools reported a Microsoft 365 credential-harvesting campaign that used Cloudflare Turnstile, IP filtering, and user-agent checks to block bots and researchers before serving phishing pages to real users. The campaign hid credential theft logic in an obfuscated custom virtual machine and could be tracked via a shared Turnstile sitekey.

Jan 1, 20266mo ago

Researchers discover exposed Roundish exploitation server

In January 2026, researchers found an open directory on 203.161.50[.]145:8889 containing a full Roundcube exploitation toolkit, operator artifacts, a Flask-based C2, a CSS-injection side-channel server, and a Go-based Linux implant. The server also contained exfiltrated data from blog.pentagonteam[.]com, including source code and secrets.

Dec 31, 20256mo ago

APT28-linked Roundish toolkit targets Ukraine's State Migration Service

The Roundish toolkit was used against mail.dmsu.gov.ua, the webmail system of Ukraine's State Migration Service, to steal credentials, exfiltrate mail and contacts, extract 2FA secrets, and establish persistence through Sieve mail-forwarding rules. Researchers assessed the activity with medium-high confidence as aligned with APT28 based on overlaps with Operation RoundPress.

Mar 10, 20251y ago

BlackSanta campaign begins targeting HR recruitment workflows

Aryaka Threat Labs reported that the BlackSanta campaign has been active for about a year, using resume-themed ISO files in recruiting channels to deliver malware. The intrusion chain culminates in a BYOVD-based payload that disables AV/EDR, Microsoft Defender protections, and system logging to support stealthy theft.

Jan 1, 20224y ago

DarkCloud infostealer begins circulating on Telegram and public storefronts

Flashpoint reported that the low-cost DarkCloud infostealer has been circulating since 2022, sold for about $30 through Telegram and public storefronts. The malware steals browser credentials, cookies, financial data, and email-application details, lowering the barrier for credential theft.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

46 LINKEDOpen in app
Threat actors
1 linked
Affected products
8 linked
Ubuntu LinuxTelegramPowershellFirefoxNginxSelinuxSentryGooglebot
Organizations
30 linked
CloudflareGoogleBleepingComputerSublime SecurityPush SecurityTikTokNICENICPalo Alto NetworksMicrosoft CorporationKonica MinoltaAmazon Web ServicesCensysSuper Micro ComputerShodanFlashpointDomainToolsNotionEsetHunt.ioDark ReadingNameCheapOracleTelegramProtonAryakaSentryURLscan.ioTechRadarIpifyAtria Convergence Technologies Limited
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.