How Can We Reduce Threats From the Initial Access Brokers Market?
ID: bc56bb35-27d0-521a-a13b-bf0f39d96606
STIX ID: report--bc56bb35-27d0-521a-a13b-bf0f39d96606
Feed Name: Dark Reading
This article describes the growing role of initial access brokers (IABs) who harvest and sell access (commonly RDP/VPN accounts, stolen credentials, and infostealer logs) to ransomware groups, increasing attack scale and efficiency; it cites observed incidents where leaked credentials on underground markets led to ransomware intrusions and recommends mitigations including enterprise-wide MFA, restricting access to corporate-managed endpoints, SSO/password vaults, logon anomaly detection, and continuous Dark Web/Open Web monitoring for leaked credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
