Datadog Security Labs · Crawled Jul 25, 2026
Getting a taste of your own medicine: Threat actor MUT-1244 targets offensive actors, leaking hundreds of thousands of credentials | Datadog Security Labs
11 IoCs 3 CVEs
Read original article ↗
AI Summary
Threat actor MUT-1244 targets offensive security actors, including pentesters and researchers, using phishing campaigns and trojanized GitHub repositories to deliver a second-stage payload. The payload exfiltrates sensitive data such as SSH keys, AWS credentials, and environment variables. Over 390,000 WordPress credentials were harvested after compromising threat actors who used a trojanized credential checker tool named 'yawpp'. The actor leverages multiple initial access methods, including malicious npm packages and phishing emails, to distribute the same backdoor.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 11 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 94[.]156[.]177[.]14 | Details → |
| IP | 37[.]120[.]193[.]124 | Details → |
| Domain | opencompiled[.]org | Details → |
| Domain | www[.]opencompiled[.]org | Details → |
| Domain | codeberg[.]org | Details → |
| GitHub Repo | k0rn66/xmrdropper | Details → |
| GitHub Repo | opencompiled-oss/kernel-patch | Details → |
| GitHub Repo | hpc20235/yawpp | Details → |
| Package | 0xengine/xmlrpc | Details → |
| Package | 0xengine/meow | Details → |
| Filename | patch-mc-0x129.sh | Details → |
MITRE ATT&CK TTPs 8 techniques
T1005 Data from Local System · Collection T1027 Obfuscated Files or Information · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1071 Application Layer Protocol · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1195 Supply Chain Compromise · Initial Access T1566 Phishing · Initial Access