Using AI to automate credential stuffing script analysis at scale

▶ Watch (00:00)

Arik Atar spent the first half of 2025 monitoring 48 Telegram channels, pulling 400-plus credential stuffing scripts, and feeding 100 of them to Claude and ChatGPT. He manually analyzed 20 to show the models what good analysis looks like, then handed the remaining 80 to AI. The research question was blunt:

“Can I train ChatGPT and Claude to analyze and research credential scripts just like I do for a living? Can I make one of my most frequent tasks over the last decade something that is fully automated?” — Arik Atar

Credential stuffing is already the number one malicious bot attack after DDoS. The reason: 84% of adults reuse the same password across 12 platforms, and ransomware groups now use it for initial access.

How credential stuffing scripts work: Silver Bullet and the three-step attack

▶ Watch (04:18)

Every script in the sample runs three steps: grab a pre-auth cookie with a CSRF token, replay it to pass session validation, then submit the credential pair. Pre-authentication exists in 100% of scripts. The tool is Silver Bullet, in its own lolly scripting language. The shortest script in the sample — lolly script walkthrough (04:52) shows all three steps in the most compact config in the dataset.

Silver Bullet 1.1.4 live attack display (06:53): 60 bots, 3 hits out of 60 attempts against an LS hosting VPS. That’s above the 1% baseline. Each row is a separate bot. PII logs in real time.

The three-actor ecosystem behind every credential stuffing attack

▶ Watch (10:14)

Three roles make up the attack chain. The config developer reverse-engineers your site, maps your bot mitigation vendor, and writes the bypass script. That script sells for $50 in Bitcoin Cash to the account cracker, who runs it without writing a single line of code. Cracked accounts go to the account buyer. Most are students skipping Spotify fees, but financial fraudsters cash out balances, drain loyalty points, and book airline tickets to resell. The script handles lockout automatically: it adds the attacker’s phone number to 2FA, deletes the victim’s email and number, and kills any path to account recovery.

Telegram marketplaces, script lifecycle, and AI-profiled threat actors

▶ Watch (12:37)

Scripts sell for 3 to 4 weeks, then get patched. Once the success rate drops, the config developer releases it free — a freemium hook to convert script kiddies into paying customers. Twenty percent of scripts end up free, living in Telegram channels and underground forums permanently.

“Three people wrote 50% of the script that we collected over six months.” — Arik Atar

Atar showed the AI-generated threat actor profile: SVB config maker (19:03) live: one actor wrote 31% of all AI-platform bypass configs for ChatGPT, Claude, Perplexity, and Gemini, specializing in CSRF token handling and CAPTCHA bypass. A second targets Samsung mobile APIs. A third builds configs for ransomware groups after Microsoft 365 and corporate SaaS accounts.

Research findings: target industries, bot volume, and hit-and-run vs low-and-slow

▶ Watch (20:59)

Tech was the top targeted industry in the sample, with AI platforms driving it there. Without AI, tech ranks fourth. Financial services, government, and travel follow. Retail scripts clustered in January 2025, one month after the 2024 holiday season, matching the sell-then-release lifecycle. Media targets averaged 107 concurrent bots and got hit-and-run attacks: a five-minute burst that drains 30,000 accounts, then gone. Financial services ran far fewer bots and ran them for days. Strict IP rate limits imposed by banking regulation force attackers to stay below the detection threshold or get blocked.

API targeting and multi-device identity spoofing as mainstream evasion

▶ Watch (26:58)

84 of the 100 scripts target API endpoints. When Atar started this research, that share was 30–40%. The shift happened because bot-mimics-human stopped working. Now scripts impersonate servers. 20% of those configs hunt legacy versions specifically. He showed Bluejet V2 API targeting — exploiting a forgotten legacy endpoint (28:38) live: the script skips V6 and hits V2, an endpoint nobody patches because nobody monitors it.

“map and monitor all of your API authentication endpoints or hackers will do it for you.” — Arik Atar

62% of scripts rotate device identity mid-attack, cycling from Android to iPhone to Mac to Windows, solving a CAPTCHA on one platform and replaying the token on another. The weakest device handles each phase.

“device identity manipulation has become a mainstream evasion technique. 62% is not an advanced technique. It’s a mainstream already.” — Arik Atar

Notable Quotes

can I train CHP and cl to analyze and research credential script just like I do for a living? Can I make my one of my most frequent task over the last decade something that is fully automated? Arik Atar · ▶ 0:56

statistically speaking, 84% of adults are recycling the same password over 12 different platforms, it’s becoming the number one bot attack that we currently have. Arik Atar · ▶ 3:16

Three people wrote 50% of the script that we collected over six months. Arik Atar · ▶ 18:43

map and monitor all of your API authentication endpoints or hackers will do it for you. Arik Atar · ▶ 29:38

device identity manipulation has become a mainstream evasion technique. 62% is not an advanced technique. It’s a mainstream already. Arik Atar · ▶ 31:26

Key Takeaways

  • AI can fingerprint individual threat actors across 100 scripts by analyzing coding style, specialization, and TTP clusters.
  • Audit and decommission legacy API versions before attackers exploit the endpoints your team stopped monitoring.
  • Defend against multi-device session switching as a first-class evasion technique, not an anomaly.

About the Speaker

Arik Atar

Arik Atar is a Senior Threat Intelligence Researcher at Radware, focusing on uncovering threat trends in underground hacker marketplaces and the application threat landscape. With over a decade of experience in cyber threat hunting, he combines strategic cyber threat analysis with social psychology. Previously at PerimeterX, Arik investigated underground bot-for-hire marketplaces, denial-of-inventory issues, and account takeover attacks. At BrightData, he led investigations for high-profile clients suspected of misusing its 100M residential IPs for cyber activity, uncovering adversaries’ tactics in DDoS and orchestrated ATO bot attacks. Arik has delivered keynotes at Defcon, APIdays, FS-ISAC, and “Fraudfighters” Cyber Defenders meetups. His education in counterterrorism and international relations from IDC University provides a strategic, macro perspective that enhances his research on threat actors.