AlienFox is a modular cloud-focused credential harvesting and spamming toolkit used to compromise email and web hosting services by extracting API keys, secrets, and configuration data from misconfigured servers and abused cloud/SaaS platforms. SentinelLABS described it as a comprehensive toolset for harvesting credentials for multiple cloud service providers and as a cloud spamming tool. Observed targeting includes AWS SES, Microsoft Office 365, and secrets associated with services such as 1and1, AWS, Bluemail, Exotel, Google Workspace, Mailgun, Mandrill, Nexmo, Office365, OneSignal, Plivo, Sendgrid, Sendinblue, Sparkpostmail, Tokbox, Twilio, Zimbra, and Zoho.
AlienFox is primarily distributed via Telegram as source code archives, with some modules also publicly available on GitHub. Researchers observed versions 2 through 4 dating from February 2022 onward. The toolkit’s targeting is described as primarily opportunistic and relies on exposed or misconfigured web applications and frameworks, especially Laravel, Drupal, Joomla, Magento, Opencart, Prestashop, and WordPress. It uses scripts to generate target lists from text files, brute-force IPs and subnets, and query OSINT sources including SecurityTrails and LeakIX. It then parses exposed environment and configuration files on susceptible servers to extract enabled services, API keys, and secrets.
Version 2 focused mainly on credential extraction from web server configuration and environment files. Its core script s3lr.py was similar to later env.py functionality. The awses.py module used the AWS Boto3 client to automate AWS Simple Email Service activity, including checking SES send quotas and retrieving email addresses from the victim account’s SES configuration. The ssh-smtp.py script parsed configuration files for credentials and used Paramiko to validate SSH configurations on targeted servers; it also contained encoded commands potentially targeting CVE-2022-31279, a rejected Laravel deserialization vulnerability. Version 3.x introduced Lar.py, which automated extraction of keys and secrets from compromised Laravel .env files and logged stolen data and targeted server details to text files. Version 4 used a bootstrap script, ALIENFOXV4.py, to launch numbered tools and added capabilities for collecting target lists, checking misconfigured targets, identifying CMS platforms, checking Amazon retail account registration status, and generating Bitcoin and Ethereum wallet seeds.
Later AlienFox versions automate post-compromise actions including AWS persistence, privilege escalation, SES quota collection, and spam operations using stolen credentials. The content also notes recurring overlap with tooling described by other researchers as Androxgh0st and GreenBot, and states that AlienFox, Greenbot, Legion, and Predator share code from an Androxgh0st-derived credential scraping module. Associated infrastructure and artifacts directly mentioned include scripts such as grabip.py, grabsite.py, s3lr.py, env.py, awses.py, ssh-smtp.py, Lar.py, and ALIENFOXV4.py.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SentinelLABS analyzed several iterations of “AlienFox,” a comprehensive toolset for harvesting credentials for multiple cloud service providers.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers use AlienFox to harvest API keys & secrets from popular services including AWS SES & Microsoft Office 365.
The target generation scripts use a combination of brute force for IPs and subnets, as well as web APIs for open-source intelligence platforms to provide details about potential targets.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cloud infostealer referenced for distribution overlap with the same Telegram channel credited in older Xeon Sender versions.
Cloud-focused attack tool family referenced as sharing Androxgh0st-derived credential scraping code and used for compromising cloud-related services.
A cloud-focused tool used for spamming activity against cloud or SaaS environments.
A modular cloud-focused credential harvesting toolkit used to collect API keys and secrets from exposed or misconfigured web servers and SaaS/cloud email services, with later versions automating abuse such as AWS persistence, privilege escalation, SES quota collection, and spam operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.