惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
云风的 BLOG
云风的 BLOG
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
Engineering at Meta
Engineering at Meta
Vercel News
Vercel News
Y
Y Combinator Blog
B
Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Check Point Blog
M
MIT News - Artificial intelligence
Jina AI
Jina AI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
Stack Overflow Blog
Stack Overflow Blog
F
Fortinet All Blogs
博客园 - 司徒正美
I
InfoQ
Google DeepMind News
Google DeepMind News
GbyAI
GbyAI
U
Unit 42

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Detecting Credential Theft to Prevent Data Breaches
Intel 471 · 2023-07-05 · via Intel 471 Blog

Cybercriminals are compromising computer networks at a greater scale than ever before. The growth of cybercrime is attributable to the availability of services and digital goods offered by cybercriminals to other cybercriminals. In the legitimate economy, this relationship is known as business-to-business commerce. In the illicit economy, it’s known as cybercrime-as-a-service. The availability of these services allows fraudsters to focus on their specialty, whether that be ransomware, credit card fraud, ID theft and more. One of the most popular if not the most popular digital goods are stolen login credentials. Unauthorized access to accounts and systems is nearly a universal trait of unlawful online activity.

Credentials are stolen in various ways, including phishing schemes, malware, social engineering and brute-force attacks. Because reusing login credentials is one of the easiest ways to compromise an organization, credentials have become one of the most sought-after products in the cybercrime-as-a-service economy. Defenses against replaying login credentials include more sophisticated monitoring of access using zero-trust principles and employing multi-factor authentication (MFA). Stronger authentication methods are also gaining in popularity due to specifications developed by the FIDO Alliance. Authentication, however, remains a weak point for organizations and a key enabler of data breaches.

Actors who sell credentials are known as initial access brokers (IABs); they sell access to fraudsters, ransomware gang affiliates and even state-sponsored actors. Sales of login credentials occur in underground forums, over Telegram and privately. Cybercriminals acquire login credentials and then reuse those credentials, gaining a foothold in the systems and allowing them to pivot deeper.

The scale is prolific. Since the start of 2023, Intel 471 has observed more than 2,000 organizations that may have been affected by credential theft in 55 industries. At least 168 different IABs have been observed. Some of the most common types of credentials sold on underground markets include those for VPN and Remote Desktop Protocol software.

[Image: Accessbroker - As of July 4, 2023, Intel 471 has counted more than 2,000 victims of credential theft across various sectors and industries.]

Intel 471 continually collects and analyses compromised credentials from the cyber underground as part of our platform’s Credential Intelligence module. The sources for credentials are varied. Credentials are sometimes openly shared by threat actors. Direct engagement with threat actors can elicit credential data. And attackers may mistakenly reveal data due to infrastructure misconfigurations.

Other types of data sets include information-stealer logs. Also known as infostealers, this type of malware is pervasively spread via methods including malicious emails (malspam), SEO poisoning and fake websites hosting trojanized versions of popular software. Infostealer malware is like an ocean fishing trawler. Once a computer is infected, the infostealer collects stored browser data, including everything from login credentials to session tokens to cryptocurrency wallet data.

This data is then packaged up into “logs” which are then often sold in bulk. These logs can be of interest to ransomware actors and other more advanced threat actors, as enterprise login credentials may be captured from home computers that have been inadvertently infected with an infostealer.

Other sources of credentials include database dumps released by threat actors and so-called “combo lists,” which are massive lists of login credentials that have been cobbled together from multiple sources. Because the advertisement and sale of access and access credentials occurs prior to an intrusion, there’s an opportunity to collect threat intelligence that can help organizations potentially avert a breach. In 2022, Intel 471 observed that it took an average of 79 days between when credentials were stolen from an organization, put up for sale on a forum, sold and then used by a ransomware affiliate. However, this span of time can be much shorter. If an organization can learn that an initial access broker is selling credentials, the affected user account can be reset. If the sale of access credentials reveals signs of a deeper compromise, an organization can launch incident response.

Using our platform, customers can monitor for credentials belonging to their employees and customers, allowing them to proactively mitigate the risks. It can also help organizations spot and manage third-party risk by monitoring their suppliers.

[Image: Accessoffered - The graph illustrates the types of access offered by initial access brokers observed so far in 2023. Initial access brokers often do not identify the victim organization or the type of access to prevent victims from taking remediative actions.]

Use cases

The Credential Intelligence module can be leveraged for several use cases. This includes receiving alerts when employee or customer credentials are compromised, if partners or third-party suppliers are affected and specifically monitoring for high-risk and/or VIP individuals within an organization. These alerts can serve as guidance for taking action before harvested credentials are used by threat actors to steal data, launch ransomware or undertake other malicious actions.

Monitor for employee credentials: This allows for alerting when credential sets belonging to employees have been identified in infostealer logs, combo lists, data breaches and more. Intel 471 subscribers can add specific domains to monitor.

Monitor for customer credentials: In this scenario, Intel 471 is monitoring for the use of compromised credentials related to an organization’s customers. It’s possible to monitor by domain for credentials belonging to customers. In some scenarios, it’s possible to monitor if those compromised customer credentials are used to log into a particular domain monitored by Intel 471.

Monitor for key third-party supplier credentials: This type of monitoring alerts about compromised credentials related to any third-party relationships such as vendors and suppliers. This is intended to quickly identify possible risk. The provided details associated with these compromised credentials are partially obfuscated, however, enough detail is retained to allow taking action on them. Monitoring third parties is an add-on service for Credential Intelligence. The details associated with compromised credentials are partially obfuscated, but enough is retained to allow taking meaningful action.

Monitor VIP credentials: VIP emails are full email addresses of high-ranking or high-risk individuals that Intel 471 will monitor. These can be corporate or private email addresses. Users are alerted if the email addresses appear in a data set.

Final Thoughts

Cybercriminals have refined malware and credential harvesting into practically industrial operations, and the scale is staggering. But as shown in this post, gathering credential data and analyzing it can result in meaningful insights that allow for pre-emptive action to avoid a data breach or ransomware attack.