logo

How are user credentials stolen and used by threat actors?

ID: 70d9f630-7959-50c5-8f2d-4235736968f1

STIX ID: report--70d9f630-7959-50c5-8f2d-4235736968f1

Feed Name: Cisco Talos

Threat Score
65/100

Date Published: 2024-02-06

Date Updated: 2026-04-27

Author: Hazel Burton

...
...

This Talos report describes the rising prevalence of credential-based intrusions where attackers use stolen or forged valid accounts to gain persistent, stealthy access. It catalogs observed techniques (phishing, fake login portals, keyloggers/infostealers, Kerberos ticket theft, brute force/password spraying, QR-code phishing, targeting dormant accounts), cites 2023 telemetry, and recommends mitigations including MFA, least-privilege access, lateral traffic inspection, account hygiene, zero-trust approaches, and active hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.