Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.
Why it matters to you
A spike in failed logins from distributed IPs is a checker run. If credentials from your domain are circulating, that run is already scheduled somewhere.
Where we meet it
Checkers are written for named targets, and sellers advertise which services they support. Seeing your own login flow named in a checker's feature list is about as direct a warning as this market issues.
Connected terms
Combolist
A recycled email:password list compiled from old breaches and other people's logs, resold in bulk. The fast food of the credential economy: cheap, stale, everywhere.
Stealer log
The complete output of an infostealer infection: every saved browser password, session cookie, autofill record and crypto-wallet file from one victim machine, zipped into a single bundle.
OTP bot
An automated calling service that impersonates a bank or provider to trick victims into reading out their one-time codes. MFA bypass, sold as a subscription.
Credential stuffing
Replaying credentials leaked from one service against every other service, at scale, on the assumption that people reuse passwords. The industrial use for every combolist and log ever sold.
Residential proxy
Traffic routed through consumer devices so it arrives from an ordinary home address. Sold by the gigabyte, sourced from paid panels and from software that enrolled the device without saying so clearly.
Read elsewhere
Where this term stops being vocabulary
Sherlog is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
ClickFix
A lure that tells the visitor the page is broken and asks them to fix it: copy this, press these keys, paste, run. The victim performs the delivery by hand, so nothing was downloaded and nothing was blocked.