Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

EMERALDWHALE:Â 15k Cloud credentials stolen in operation targeting exposed Git config files

Blog post from Sysdig

Post Details
Company
Date Published
Author
Miguel Hernández
Word Count
2,766
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

EMERALDWHALE, a global cyber operation uncovered by the Sysdig Threat Research Team, targeted exposed Git configuration files, leading to the theft of over 15,000 cloud service credentials. The operation exploited misconfigured web services to steal credentials, clone private repositories, and extract cloud credentials from source code, with the stolen data primarily used for phishing and spam. The credentials, which can be worth hundreds of dollars per account, were stored in an S3 bucket of a previous victim, highlighting the inadequacy of secret management alone in securing environments. The attack utilized tools like MZR V2 and Seyzo-v2 to scan the internet for exposed Git configurations, exploiting these files to access private repositories and extract sensitive information. This incident underscores the booming underground market for credentials, particularly those of cloud services, and emphasizes the need for comprehensive exposure management and vulnerability scanning to prevent similar breaches.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 3 1,022 103 53 -20%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.