This is the defining step. An attacker will run the combolist through a "checker" (e.g., OpenBullet, SilverBullet, or SentryMBA) configured with a specific "config" file for a target website. The config tells the checker how to talk to the website's login API.

The cybercrime ring began to execute their phishing campaign, but they were met with a series of unexpected obstacles. The financial institution's security team, alerted by Alex's earlier warnings, was prepared and successfully blocked most of the phishing attempts.

This process is known as . It is a brute-force attack that relies on automation. A checker might test thousands of email/password combinations against a streaming service in a matter of minutes. When a successful login is found (a "hit"), the software saves the account details.