Datadog Security Labs · Crawled Jul 25, 2026

Getting a taste of your own medicine: Threat actor MUT-1244 targets offensive actors, leaking hundreds of thousands of credentials | Datadog Security Labs

11 IoCs 3 CVEs
Read original article ↗

AI Summary

Threat actor MUT-1244 targets offensive security actors, including pentesters and researchers, using phishing campaigns and trojanized GitHub repositories to deliver a second-stage payload. The payload exfiltrates sensitive data such as SSH keys, AWS credentials, and environment variables. Over 390,000 WordPress credentials were harvested after compromising threat actors who used a trojanized credential checker tool named 'yawpp'. The actor leverages multiple initial access methods, including malicious npm packages and phishing emails, to distribute the same backdoor.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 11 extracted

Type Value Detail
IP 94[.]156[.]177[.]14 Details →
IP 37[.]120[.]193[.]124 Details →
Domain opencompiled[.]org Details →
Domain www[.]opencompiled[.]org Details →
Domain codeberg[.]org Details →
GitHub Repo k0rn66/xmrdropper Details →
GitHub Repo opencompiled-oss/kernel-patch Details →
GitHub Repo hpc20235/yawpp Details →
Package 0xengine/xmlrpc Details →
Package 0xengine/meow Details →
Filename patch-mc-0x129.sh Details →

MITRE ATT&CK TTPs 8 techniques