Expel Quarterly Threat Report volume IV (Q1 2024): suspicious authentication sources
ID: c5b61a7f-359c-5247-8f9d-78934bcea697
STIX ID: report--c5b61a7f-359c-5247-8f9d-78934bcea697
Feed Name: Expel Blog
Threat Score
This Q1 Quarterly Threat Report highlights identity-related incidents observed by the SOC, emphasizing AiTM credential-harvesting campaigns that capture credentials and bypass MFA. It documents attacker techniques—frequent use of hosting providers/VPS (42%), VPNs/TOR (19%), residential proxies (4%), and geolocation anomalies (28%)—and recommends mitigations such as enforcing MFA plus additional restrictions like requiring authentication from managed devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
