MEDIUMMalware
Global

UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications

Thursday, April 2, 2026 at 10:00 AM UTC·Source: Cisco Talos

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

Talos is disclosing a large-scale automated credential harvesting campaign carried out by a threat cluster we currently track as UAT-10608. The campaign is primarily leveraging a collection framework dubbed “NEXUS Listener.”

Analysis

Talos is disclosing a large-scale automated credential harvesting campaign carried out by a threat cluster we currently track as UAT-10608. The campaign is primarily leveraging a collection framework dubbed “NEXUS Listener.”
Source Attribution

Originally published by Cisco Talos on Apr 2, 2026.

Related Threats