Hackers Using E-Crime Tool Atlantis AIO for Credential Stuffing on 140+ Platforms

Hackers Using E-Crime Tool Atlantis AIO for Credential Stuffing on 140+ Platforms

Mar 26, 2025Ravie LakshmananPassword Safety / Cybercrime

Risk actors are leveraging an e-crime software referred to as Atlantis AIO Multi-Checker to automate credential stuffing assaults, in keeping with findings from Irregular Safety.

Atlantis AIO “has emerged as a strong weapon within the cybercriminal arsenal, enabling attackers to check thousands and thousands of stolen credentials in speedy succession,” the cybersecurity firm said in an evaluation.

Credential stuffing is a sort of cyber assault wherein an adversary collects stolen account credentials, usually consisting of lists of usernames or electronic mail addresses and passwords, after which makes use of them to realize unauthorized entry to person accounts on unrelated programs by large-scale automated login requests.

Cybersecurity

Such credentials could possibly be obtained from a knowledge breach of a social media service or be acquired from underground boards the place they’re marketed on the market by different menace actors.

Credential stuffing can also be completely different from brute-force assaults, which revolve round cracking passwords, login credentials, and encryption keys utilizing a trial and error methodology.

Atlantis AIO, per Irregular Safety, provides menace actors the power to launch credential stuffing assaults at scale through pre-configured modules for focusing on a variety of platforms and cloud-based providers, thereby facilitating fraud, knowledge theft, and account takeovers.

“Atlantis AIO Multi-Checker is a cybercriminal software designed to automate credential stuffing assaults,” it stated. “Able to testing stolen credentials at scale, it might probably rapidly try thousands and thousands of username and password combos throughout greater than 140 platforms.”

E-Crime Tool Atlantis AIO

The menace actors behind this system additionally declare that it is constructed on “a basis of confirmed success” and that they’ve hundreds of glad shoppers, whereas assuring prospects of the safety ensures baked into the platform as a way to hold their buy personal.

“Each characteristic, replace, and interplay is crafted with meticulous consideration to raise your expertise past expectations,” they state within the official commercial, including “we frequently pioneer options that drive unprecedented outcomes.”

Targets of Atlantis AIO embody electronic mail suppliers like Hotmail, Yahoo, AOL, GMX, and Internet.de, in addition to e-commerce, streaming providers, VPNs, monetary establishments, and meals supply providers.

Cybersecurity

One other notable side of the software is its means to conduct brute-force assaults in opposition to the aforementioned electronic mail platforms and automate account restoration processes related to eBay and Yahoo.

“Credential stuffing instruments like Atlantis AIO present cybercriminals with a direct path to monetizing stolen credentials,” Irregular Safety stated.

“As soon as they achieve entry to accounts throughout numerous platforms, attackers can exploit them in a number of methods — e.g., promoting login particulars on darkish net marketplaces, committing fraud, or utilizing compromised accounts to distribute spam and launch phishing campaigns.”

To mitigate the account takeover dangers posed by such assaults, it is advisable to enact strict password guidelines and implement phishing-resistant multi-factor authentication (MFA) mechanisms.

Discovered this text fascinating? Observe us on Twitter and LinkedIn to learn extra unique content material we submit.

Leave a Reply