A combolist, short for "combination list," is a type of credential list that contains pairs of usernames and passwords. These lists are often compiled by threat actors through various means, including phishing campaigns, data breaches, and malware infections. Combolists can be used for a range of malicious activities, such as credential stuffing, account takeover, and brute-force attacks.
: In underground forums, "private" often implies the data has not been widely leaked or shared before, making it more valuable for "credential stuffing" attacks because the passwords are less likely to have been changed yet. How These Lists Are Used
A combolist, short for "combination list," is a type of credential list that contains pairs of usernames and passwords. These lists are often compiled by threat actors through various means, including phishing campaigns, data breaches, and malware infections. Combolists can be used for a range of malicious activities, such as credential stuffing, account takeover, and brute-force attacks.
: In underground forums, "private" often implies the data has not been widely leaked or shared before, making it more valuable for "credential stuffing" attacks because the passwords are less likely to have been changed yet. How These Lists Are Used