MEDIUMMalware
Global
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
Thursday, April 2, 2026 at 10:00 AM UTC·Source: Cisco Talos
Updated: Thursday, April 2, 2026 at 05:46 PM UTC
Executive Summary
Talos is disclosing a large-scale automated credential harvesting campaign carried out by a threat cluster we currently track as UAT-10608. The campaign is primarily leveraging a collection framework dubbed “NEXUS Listener.”
Analysis
Talos is disclosing a large-scale automated credential harvesting campaign carried out by a threat cluster we currently track as UAT-10608. The campaign is primarily leveraging a collection framework dubbed “NEXUS Listener.”