SSH Brute is a custom hacking tool used by Cameron John Wagenius (alias "kiberphant0m") and his co-conspirators between April 2023 and December 2024 to obtain network credentials from major telecommunications companies, including AT&T and Verizon. The tool was specifically designed for brute-forcing SSH credentials, enabling unauthorized access to targeted networks. Compromised credentials were shared via encrypted Telegram chats and used to facilitate further cybercriminal activities, such as extortion, SIM-swapping, and data theft. The group advertised and sold stolen data on cybercrime forums like BreachForums and XSS.is, and used the access gained through SSH Brute to attempt extortion of at least $1 million from victims. The malware was part of a broader campaign targeting at least ten organizations, primarily in the telecommunications sector. High-confidence indicators include its use for SSH brute-forcing, credential theft, and its role in enabling subsequent fraud and extortion schemes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The group obtained login credentials for the organizations’ protected computer networks, in part by using a hacking tool called SSH Brute that Wagenius helped develop.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.