Cloud Security, Data Security

Zestix hackers sell data stolen from ShareFile, Nextcloud

Hacker attack. Security alert, system hacked, internet cyber attack concept with red broken padlock, cybersecurity. Compromised password.

A cybercriminal actor known as Zestix is allegedly selling massive volumes of sensitive corporate data stolen from dozens of organizations by breaching their ShareFile, Nextcloud, and OwnCloud file-sharing platforms, reports Bleeping Computer.

According to a report by threat intelligence firm Hudson Rock, the initial access was likely gained using employee credentials harvested by prevalent info-stealing malware like RedLine, Lumma, and Vidar, often delivered via malvertising or "ClickFix" attacks. The attackers then exploited the absence of multi-factor authentication to log into these corporate cloud services. Hudson Rock's analysis, which correlated its infostealer data with public sources, identified at least 15 victim organizations across critical sectors including aviation, defense, healthcare, utilities, and government, where compromised credentials had been present in criminal databases for years without being rotated.

The actor, operating as an Initial Access Broker, offers stolen datasets ranging from gigabytes to terabytes, purportedly containing highly sensitive materials such as aircraft maintenance manuals, health records, government contracts, and network configurations.

UPDATE: Progress Software issued the following statement to SC Media on Jan. 8: "Hudson Rock’s investigation found that these recent compromises of corporate file-sharing portals — including ShareFile instances — were the result of client user credentials being stolen and were not the result of platform vulnerabilities. These credentials were stolen via malware on client machines. Based on Hudson Rock's analysis, the threat actor used these valid credentials to log into client environments where multi-factor authentication was not enforced, which enabled unauthorized access to the clients’ environments. Progress continues to emphasize the importance of utilizing multi-factor authentication as a widely recognized control to help mitigate the risk of credential-based attacks."

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds