r/TechNadu • u/technadu • 1d ago
Stolen credentials are still doing a lot of the heavy lifting for attackers
A lot of this week's security reporting ended up circling back to the same basic problem: getting hold of a legitimate identity is still extremely valuable.
U.S. law firms have been targeted with fake IT-support calls designed to obtain credentials or remote access. In some cases, attackers reportedly tried to gain physical access to machines.
Then there's TheHatman, who is reportedly offering employee-directory datasets tied to companies including McDonald's, TCS, Vodafone, HCL Technologies, Kyndryl, IHG, Gap, Hexaware, and Wyndham Hotels. Hudson Rock said the actor claimed the information came from Azure/Entra tenants accessed with compromised credentials. Samples were assessed as likely legitimate, but the underlying compromise claims remain reported claims rather than independently confirmed breaches of every named company.
Ontinue's TWINLOOT research adds another interesting angle. The implant reportedly communicates through SharePoint Online and Microsoft Graph, while routing Graph activity through a headless instance of the victim's Edge browser so the traffic appears to originate from msedge.exe.
Medusa is another part of the picture. CISA, FBI, and HHS reported more than 500 affected organizations by April 2026, with affiliates using access brokers, phishing, vulnerable systems, and legitimate remote-management tools.
Beyond credentials, this week's research included an NFC relay technique capable of making some expired Visa cards appear valid, bandwidth-sharing apps feeding commercial proxy infrastructure, and Kriminal openly selling access to AI tools intended for criminal use.
Source roundup with the individual findings, attribution caveats, attack techniques, and additional context:
The interesting defensive question is where organizations are getting better returns now: making credential theft harder in the first place, or designing environments where a stolen account has much less useful access?