Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.Β
How does water holing attack work?
- Β The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
π Free Password Audit Tools Youβll Be Grateful For π
Weak or reused passwords remain a major entry point for attackers, yet many organizations lack visibility into credential risks. These free password audit tools help CISOs identify vulnerabilities before attackers exploit them.
Here are the top free password audit tools:
1οΈβ£ Have I Been Pwned β Check if employee credentials have appeared in breaches.
π https://haveibeenpwned.com/
2οΈβ£ L0phtCrack Free Edition β Audit password strength and cracking susceptibility.
π https://www.l0phtcrack.com/
3οΈβ£ KeePassXC Password Analysis β Open-source password manager with audit capabilities.
π https://keepassxc.org/
4οΈβ£ John the Ripper (Community Edition) β Test password strength using hash cracking simulations.
π https://www.openwall.com/john/
5οΈβ£ Hashcat (Free Edition) β Advanced password auditing tool for security testing.
π https://hashcat.net/hashcat/
6οΈβ£ AUMINT Credential Risk Analyzer (Free Demo) β Combines password auditing with human risk simulations.
π https://aumint.io/resources
7οΈβ£ CyberArk Free Password Check Tools β Identify weak, reused, or compromised passwords across your environment.
π https://www.cyberark.com/resources/free-tools/
β‘ Takeaway: These free tools help CISOs detect weak credentials, reduce attack surfaces, and enforce stronger password policies, saving time and reducing breach risk.
At AUMINT.io, we go beyond technical checks by simulating phishing and social engineering attacks to see which users are most likely to compromise credentials.
π Want to uncover hidden credential risks in your organization? Book a free demo
#PasswordSecurity #CISO #CyberSecurity #CredentialRisk #AUMINT