UAT-10608 is a threat cluster observed by Cisco Talos conducting a large-scale, automated credential-harvesting campaign against public-facing web applications, especially Next.js deployments, using a custom framework called NEXUS Listener to extract and exfiltrate secrets such as credentials, SSH keys, cloud tokens, and API keys. The activity has been linked to broad opportunistic scanning and at least 766 compromised hosts across multiple regions and cloud providers.
UAT-10608 is a threat cluster tracked by Cisco Talos that conducts large-scale automated credential-harvesting campaigns, specifically targeting Next.js web applications using a custom framework called NEXUS Listener to steal secrets such as SSH keys, cloud tokens, and API keys.
What framework is associated with UAT-10608's activity?+
The activity of UAT-10608 is associated with a custom framework named NEXUS Listener.