Automated Next.js Exploit Powers Centralized Credential Harvesting Service
A threat cluster named UAT-10608 is exploiting a known Next.js vulnerability (CVE-2025-55182) to compromise at least 766 hosts globally. The attackers use automated scripts to extract credentials, SSH keys, cloud tokens, and environment secrets from these hosts. Stolen data is aggregated and analyzed through a web-based C2 GUI called "NEXUS Listener," which provides operators with detailed statistics and search capabilities. This setup enables rapid reuse or bulk sale of harvested credentials, turning isolated exploits into a scalable credential-harvesting service.
The campaign targets publicly accessible Next.js applications, likely identified via internet scanning services like Shodan or Censys. The presence of a centralized GUI for stolen data means defenders must go beyond patching. They need to identify compromised hosts, rotate all exposed credentials and keys, and hunt for signs of the multi-phase harvester and C2 traffic. This is a high-priority threat for teams running Next.j