[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPyv7aNEQkNqhsG8rSOJLWSJNSrjfDLHfxIPNUuE1PVw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"2b2c3f17-e816-4f6f-8180-7ddee69ad5f7","ransomware-groups-shift-to-credential-based-attacks","be9652ee-0000-41ed-adee-da915a079eb5","Ransomware Groups Shift to Credential-Based Attacks","Ransomware operators like the SPIDER threat group are abandoning traditional exploit-based attacks in favor of compromising legitimate credentials through social engineering and credential harvesting. This tactical shift exploits weaknesses in identity and access management systems rather than technical vulnerabilities, making attacks harder to detect since they appear as legitimate user activity. Organizations with poor credential hygiene, weak multi-factor authentication, and inadequate user training become easy targets for these credential-focused attacks.","**Immediate actions:**\n- Enforce multi-factor authentication on all critical systems and remote access points\n- Conduct immediate password reset for privileged accounts and implement password complexity requirements\n- Review and disable unused or dormant user accounts across all systems\n\n**Long-term improvements:**\n- Implement zero-trust architecture with continuous identity verification and least-privilege access\n- Deploy privileged access management (PAM) solutions to control and monitor administrative credentials\n- Establish regular access reviews and automated account lifecycle management processes\n\n**Detection measures:**\n- Monitor for unusual login patterns, failed authentication attempts, and credential usage anomalies\n- Implement user and entity behavior analytics (UEBA) to detect compromised account activity\n- Enable comprehensive logging of all authentication events and privileged access activities",[12,13,14,15,16,17],"CIS Control 6","CIS Control 5","NIST AC-2","NIST AC-3","NIST IA-2","ISO 27001 A.9.2","published","2026-04-02T16:08:07.720367+00:00","2026-04-02T16:08:07.581+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fx.com\u002FCrowdStrike\u002Fstatus\u002F2039729772180222287","ransomware-isn-t-breaking-into-your-network-anymore-it-s-logging-in-adversaries-","Ransomware isn't breaking into your network anymore… it's logging in. 🔑\n\nAdversaries have moved...",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]