A threat actor known as Zestix has systematically breached dozens of major global enterprises by exploiting credentials harvested from infostealer malware such as RedLine, Lumma, and Vidar. These infostealers, often distributed through malvertising or phishing, collect login data from infected employee devices, which is then aggregated and sold or used on underground forums. Zestix specifically targeted cloud file-sharing platforms including ShareFile, Nextcloud, and OwnCloud, gaining unauthorized access to sensitive corporate data across sectors like aviation, defense, healthcare, utilities, and government. The breaches were enabled by the widespread absence of Multi-Factor Authentication (MFA), allowing attackers to use valid credentials—some of which had been exposed for years—to access and exfiltrate terabytes of confidential information.
Security researchers from multiple firms, including Hudson Rock and InfoStealers, highlighted that Zestix operates as an initial access broker, auctioning access to compromised cloud environments and datasets. The attacks underscore a critical security gap: organizations' failure to implement or enforce MFA and to regularly rotate credentials, leaving them vulnerable to credential-based attacks. The scale and persistence of these breaches demonstrate the urgent need for improved credential hygiene and robust access controls to protect cloud-based assets from similar threats.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers warned that thousands of infected endpoints at major companies and broadly circulating infostealer logs could leave many more organizations exposed beyond the already identified victims. The campaign was described as ongoing, with MFA enforcement and credential rotation urged as immediate mitigations.
As the story developed, multiple reports described Zestix/Sentap as a lone Iranian national and linked the actor to the FunkSec ransomware group. This expanded attribution beyond the initial access-brokering activity and data theft reporting.
Subsequent coverage named victims including Iberia Airlines, Pickett & Associates, Intecro Robotics, Maida Health, CRRC MA, CiberC, Sekisui House, and K3G Solutions. Reports said the actor exposed or sold terabytes of sensitive corporate, healthcare, military, and infrastructure data.
Hudson Rock publicly reported the campaign, describing how years-old infostealer logs and poor credential hygiene enabled access to enterprise cloud platforms. The company said it had notified ShareFile and planned to alert Nextcloud and OwnCloud.
By early 2026, researchers had tied Zestix to breaches at roughly 50 organizations, with at least 15 confirmed and about 30 more potential victims identified. The intrusions were enabled by valid credentials from RedLine, Lumma, and Vidar infections, often on accounts lacking MFA.
Over the course of the campaign, Zestix operated as an initial access broker, advertising compromised cloud accounts and auctioning stolen corporate data on Russian-language and other underground forums. The material included sensitive files such as defense blueprints, healthcare records, utility data, and aviation documentation.
From late 2024, the threat actor known as Zestix/Sentap began compromising ShareFile, Nextcloud, and OwnCloud accounts using credentials stolen by infostealer malware rather than software exploits. The activity affected organizations across sectors including defense, healthcare, finance, utilities, aviation, and government.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcedarkreading.com
Open sourcerescana.com
Open sourcego.theregister.com
Open sourcegovinfosecurity.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.