How are user credentials stolen and used by threat actors?
ID: 70d9f630-7959-50c5-8f2d-4235736968f1
STIX ID: report--70d9f630-7959-50c5-8f2d-4235736968f1
Feed Name: Cisco Talos
This Talos report describes the rising prevalence of credential-based intrusions where attackers use stolen or forged valid accounts to gain persistent, stealthy access. It catalogs observed techniques (phishing, fake login portals, keyloggers/infostealers, Kerberos ticket theft, brute force/password spraying, QR-code phishing, targeting dormant accounts), cites 2023 telemetry, and recommends mitigations including MFA, least-privilege access, lateral traffic inspection, account hygiene, zero-trust approaches, and active hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
