logo

Expel Quarterly Threat Report volume IV (Q1 2024): suspicious authentication sources

ID: c5b61a7f-359c-5247-8f9d-78934bcea697

STIX ID: report--c5b61a7f-359c-5247-8f9d-78934bcea697

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2024-04-18

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

This Q1 Quarterly Threat Report highlights identity-related incidents observed by the SOC, emphasizing AiTM credential-harvesting campaigns that capture credentials and bypass MFA. It documents attacker techniques—frequent use of hosting providers/VPS (42%), VPNs/TOR (19%), residential proxies (4%), and geolocation anomalies (28%)—and recommends mitigations such as enforcing MFA plus additional restrictions like requiring authentication from managed devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.