Threats · 166 days ago
A threat cluster named UAT-10608 is exploiting a known Next.js vulnerability (CVE-2025-55182) to compromise at least 766 hosts globally. The attackers use automated scripts to extract credentials, SSH keys, cloud tokens, and environment secrets from these hosts. Stolen data is aggregated and analyzed through a web-based C2 GUI called "NEXUS Listener," which provides operators with detailed statistics and search capabilities. This setup enables rapid reuse or bulk sale of harvested credentials, turning isolated exploits into a scalable credential-harvesting service.
The campaign targets publicly accessible Next.js applications, likely identified via internet scanning services like Shodan or Censys. The presence of a centralized GUI for stolen data means defenders must go beyond patching. They need to identify compromised hosts, rotate all exposed credentials and keys, and hunt for signs of the multi-phase harvester and C2 traffic. This is a high-priority threat for teams running Next.j
1 source covering this story
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
Talos is disclosing a large-scale automated credential harvesting campaign carried out by a threat cluster we currently track as UAT-10608.
Part of the PlainSec briefing for 2026-04-02