HUGENETWORKS


HUGENETWORKS
PTEN
←new lookup

huge-networks.com

Computer & Network Security · 51-200 · Sao Paulo · Brazil
checked at 08/20, 05:28 AM · Argus intelligence base

RiskMedium

93
Compromised machines
holding credentials for this domain
5
Employees
with exposed credential
88
Customers
with exposed credential
165 days ago
Last infection
141 days ago
Last database load
4 observations
  • The 20 machines in this sample held credentials for 26974 third-party services
  • Windows Defender was installed on 14 machines and did not stop the infection
  • 6 of 20 graded passwords are classified as weak
  • Remote access credential exposed
Exposed identity surface

No sensitive application identified in this sample.

Active sessions captured
934of 4,117 session cookies still valid, across 15 machines in this sample

A valid session cookie asks for no password and no second factor — whoever holds it does not log in, they continue a login that already happened.

Services with a live session

  • google.com443
  • facebook.com105
  • canva.com76
Credential sample
TypePasswordMachineStealerDate
employee••••••••• 9 · Aa1@DESKTOP-•••••00RedLine03/09/26
customer•••••••••• 10 · Aa1@DESKTOP-•••••11Lumma04/10/26
third party••••••••••• 11 · Aa1@DESKTOP-•••••22Vidar05/11/26
customer•••••••••••• 12 · Aa1@DESKTOP-•••••33StealC06/12/26
Type
employee
Password
••••••••• 9 · Aa1@
Machine
DESKTOP-•••••00
Stealer
RedLine
Date
03/09/26
Type
customer
Password
•••••••••• 10 · Aa1@
Machine
DESKTOP-•••••11
Stealer
Lumma
Date
04/10/26
Type
third party
Password
••••••••••• 11 · Aa1@
Machine
DESKTOP-•••••22
Stealer
Vidar
Date
05/11/26
Type
customer
Password
•••••••••••• 12 · Aa1@
Machine
DESKTOP-•••••33
Stealer
StealC
Date
06/12/26

Enter your corporate email to view

93 compromises in total · masked sample below

What was on the machines

Measured across the 20 machines in this sample, not extrapolated to the total · first 20 machines

Credentials by type

  • Customer19
  • Third party1

Password strength

  • Weak4
  • Medium2
  • Strong12
  • Not graded2
Most recent records20 of 93

Infostealer families

20machines
  • Lumma1260%
  • Generic Stealer420%
  • Vidar210%
  • Acreed15%
  • RedLine15%

Systems

  • Windows 11 Pro
  • Windows 11
  • Windows 10 Pro
  • Windows 11 Pro (10.0.21996) x64
  • Windows 11 Pro (10.0.22631) x64
  • Windows 11 24H2 build 26100 (64 Bit)
  • Windows 10 Enterprise LTSC (10.0.19044) x64

This is a masked sample from a one-off lookup. In Argus the monitoring is continuous: you see the full credential, the machine, the history, the discovered assets and the remediation workflow.

Book a conversation

Where this data comes from

The data comes from machines infected by an infostealer — not from any access to the company you searched for. We do not break in, we do not scan and we do not test anything of theirs.

Passwords, session tokens, e-mail addresses and full identifiers never leave the server: masking is applied before the page is assembled.

Understand the method and the limits

An infostealer is a program that copies saved passwords, session cookies and browser history from the infected machine and ships all of it to whoever ran it. Those files then circulate on forums and closed channels, and that is where specialised intelligence providers recover them. We consolidate those bases.

Two limits worth stating. A record proves the credential was exposed on the date shown, not that it still works today. And the sample on screen is a slice of the base, not the total — sample figures always state how many machines they were measured on.

Attack infrastructure tracked right now

measured at 08/20, 04:28 AM
64,421
C2 servers

active infostealers

30,463
PhaaS hosts

phishing as a service

4,328
ClickFix sites

clipboard hijacking

samsung.com
68
  • linkedin.com44
  • miro.com35
  • datascroll.com.br32
  • live.com25
  • Third-party services

    credentials for other services on the same machines

    26,974

    Antivirus present

    installed and did not stop the infection

    • Windows Defender15 machines

    Log depth

    An infostealer does not stop at passwords: it inventories the programs installed on the machine and the browser search history. It is a portrait of what the person uses at work and what they looked for — which is why a log is worth more to an attacker than a list of credentials.

    952

    installed programs

    Programs found on the machines

    Software inventory the infostealer took along with the passwords. No version numbers, on purpose: the version identifies the machine and adds nothing to the argument. The count is of machines the program appeared on.

    • MVMicrosoft Visual C++ 2022 X64 Additional Runtime12 mach.
    • MVMicrosoft Visual C++ 2022 X64 Minimum Runtime12 mach.
    • MVMicrosoft Visual C++ 2008 Redistributable - x8611 mach.
    • MVMicrosoft Visual C++ 2012 x64 Additional Runtime11 mach.
    • MVMicrosoft Visual C++ 2012 x64 Minimum Runtime11 mach.
    • MVMicrosoft Visual C++ 2015-2022 Redistributable11 mach.
    • MVMicrosoft Visual C++ 2022 X86 Additional Runtime11 mach.
    • MVMicrosoft Visual C++ 2022 X86 Minimum Runtime11 mach.
    • MVMicrosoft Visual C++ 2010 x64 Redistributable10 mach.
    • MVMicrosoft Visual C++ 2010 x86 Redistributable10 mach.
    • MVMicrosoft Visual C++ 2012 x86 Additional Runtime10 mach.
    • MVMicrosoft Visual C++ 2012 x86 Minimum Runtime10 mach.
    • MVMicrosoft Visual C++ 2013 x86 Additional Runtime10 mach.
    • MVMicrosoft Visual C++ 2013 x86 Minimum Runtime10 mach.
    • MVMicrosoft Visual C++ 2013 Redistributable9 mach.
    • MVMicrosoft Visual C++ 2012 Redistributable8 mach.
    • NFNVIDIA FrameView SDK7 mach.
    • NSNVIDIA ShadowPlay7 mach.
    • NSNVIDIA Software do sistema PhysX7 mach.
    • NVNVIDIA Virtual Audio7 mach.
    • ANAplicativo NVIDIA6 mach.
    • MVMicrosoft Visual C++ 2008 Redistributable - x646 mach.
    • MVMicrosoft Visual C++ 2013 x64 Additional Runtime6 mach.
    • MVMicrosoft Visual C++ 2013 x64 Minimum Runtime6 mach.
    14,093

    captured searches

    across the 20 machines whose log carried that history

    Where they searched

    The log carries the browser search history — engine by engine, with what was typed.

    • Google11,328
    • YouTube1,806
    • Bing642
    • Perplexity132
    • X63
    • ChatGPT
    Aug 24Mar 07
  • Windows 10 Pro (10.0.19045) x64
  • Windows 11 Pro (10.0.26100) x64
  • Windows 11 Home Single Language (10.0.22621) x64
  • Windows 10 Home x64
  • Windows 11 Home (10.0.22631) x64
  • 56
  • Yahoo49
  • Brave17