How Attackers Use Stolen Credentials: The Complete Account Takeover Lifecycle
ID: 4f794d95-b103-57ed-9f5b-324ed7871b57
STIX ID: report--4f794d95-b103-57ed-9f5b-324ed7871b57
Feed Name: Brandefense Blog
This report describes the full credential-to-account-takeover lifecycle: how credentials are harvested (breaches, infostealers, phishing, guessing), aggregated and sold as combolists, and then used with open-source tooling (OpenBullet 2), residential proxy networks, CAPTCHA-solving and fingerprint spoofing to perform large-scale credential stuffing leading to account takeover. It covers post-compromise actions (session cookie replay, OAuth persistence, email rules), the underground economics (pricing of combolists and hits), and detection opportunities at each stage, recommending external credential intelligence and phishing-resistant MFA as high-impact defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
