FIORA NIGHT: Exposing a Credential Harvesting Botnet
Credential theft has evolved into highly automated operations that scan the internet at scale, validate stolen secrets in real time, and immediately weaponize them for phishing, fraud, and infrastructure abuse.
FIORA NIGHT: A Credential Harvesting Botnet Exposed presents SOCRadar Threat Intelligence’s investigation into a financially motivated credential-harvesting and phishing operation publicly branded “REZ.” The report analyzes the actor’s exposed infrastructure, custom tooling, attack chain, credential collection methods, command-and-control operations, and victim impact, revealing how a single operation harvested thousands of valid credentials across organizations in more than 75 countries.
Drawing on analysis of 9,041 recovered files (6.6 GB), live Telegram command-and-control intelligence, exposed phishing infrastructure, and recovered source code, the report details how the operation exploited exposed configuration files, cloud credentials, Git repositories, AI provider keys, and known vulnerabilities to build a scalable credential-harvesting ecosystem. It also examines the actor’s infrastructure, phishing operations, MITRE ATT&CK mapping, indicators of compromise, and recommendations to help organizations identify and respond to related threats.
➡️ Download the full whitepaper to explore the complete investigation, review the technical findings, and strengthen your organization’s defenses against credential theft and phishing campaigns.
Key Highlights:
- Complete analysis of the FIORA NIGHT (“REZ”) infrastructure, tooling, and operator profile
- Breakdown of the botnet’s credential harvesting pipeline, phishing operations, and nine-phase attack chain
- Analysis of active exploitation targeting vulnerabilities including Log4Shell, ChromaDB, Ghost CMS, and BeyondTrust
- Intelligence on verified compromised credentials, exposed cloud assets, AI provider keys, GitHub tokens, and phishing infrastructure
- Comprehensive indicators of compromise (IOCs), MITRE ATT&CK mapping, victim distribution, and defensive recommendations for security teams
Whether you’re a threat intelligence analyst, SOC team, incident responder, security researcher, or cyber defense leader, this whitepaper provides an in-depth look at how modern credential-harvesting operations are built, operated, and scaled—and how defenders can detect and disrupt them.
