Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents

Unit 42: Identity Compromise Is the Primary Attack Vector in (TL-2026-1938) is a high-severity tracked intrusion set, first published 2026-08-08. It is attributed to Scattered Spider with high confidence, affects Okta Okta Identity Platform, maps to 17 MITRE ATT&CK techniques (T1003.006, T1021.001, T1069.003), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-1938

Threat ID
TL-2026-1938
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-08-08
Last reviewed
2026-08-08
Attribution
Scattered Spider
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
technology, business process outsourcing, telecoms, hospitality, financial services, gaming, retail, managed service providers, manufacturing
Target regions
North America
Detection rules
9
Indicators of compromise
18

Malware and tooling in Unit 42: Identity Compromise Is the Primary Attack Vector in

Malware and tooling: ALPHV/BlackCat, AnyDesk, DragonForce, MimiKatz, Raccoon Stealer - S1148, SharpHound, TeamViewer, 0ktapus phishing kit, AnyDesk, ConnectWise ScreenConnect, Mimikatz, RSocx

Unit 42's 'Inside the Modern SOC: The Identity Front Door' report finds identity weaknesses played a role in nearly 90% of investigated incidents, with 65% of initial access activity involving identity-based techniques and 87% of incidents spanning multiple attack surfaces. The report cites Muddled Libra (Scattered Spider) as the exemplar of identity-abuse tradecraft: help-desk impersonation, MFA fatigue/bypass, and social engineering to defeat traditional perimeter controls.

How Unit 42: Identity Compromise Is the Primary Attack Vector in works

Palo Alto Networks Unit 42 published 'Inside the Modern SOC: The Identity Front Door' on 2026-08-07 (author Sharon Maydar), synthesizing incident-response findings across Unit 42's investigated caseload. The headline findings: identity weaknesses factored into roughly 90% of incidents investigated; 65% of initial-access activity specifically involved identity-based techniques (credential theft, MFA manipulation, session hijacking, and social engineering); and 87% of incidents spanned multiple attack surfaces (endpoint, cloud, SaaS, and network) rather than staying contained to a single domain. Unit 42 describes a repeatable attack progression: initial identity compromise, followed by persistence and account expansion, privilege escalation, multi-domain lateral movement, and finally objective achievement — ransomware deployment, data theft, financial fraud, or long-term persistent access.

The report cites Muddled Libra (publicly tracked as Scattered Spider, UNC3944, Octo Tempest, and Storm-0875) as the clearest example of this identity-first tradecraft. Muddled Libra is a native-English-speaking, financially motivated cybercrime group active since at least 2022. Rather than exploiting software vulnerabilities, the group's signature technique is social-engineering help-desk and IT-support staff by phone or SMS: callers impersonate a locked-out employee, pressure the agent into resetting the target's password and/or MFA method, and then enroll an attacker-controlled device for future MFA approvals. Where help-desk impersonation is not viable, the group instead floods a target with repeated MFA push notifications ('MFA fatigue' / MFA bombing) until the victim approves one out of frustration. Unit 42 has documented cases where this chain took the group from initial contact to domain administrator rights in under 40 minutes without deploying any malware.

Muddled Libra emerged from the 0oktapus/0ktapus phishing-kit ecosystem in 2022, initially targeting CRM, business-process-outsourcing (BPO), and telecommunications firms before expanding in 2023 into gaming, hospitality, retail, MSP, manufacturing, and financial-services targets. In 2023 the group joined the ALPHV/BlackCat ransomware-as-a-service affiliate program; a joint CISA/FBI advisory (AA23-320A) was first issued 2023-11-16 and substantially updated 2025-07-29 to document new tradecraft including DragonForce ransomware deployment and Snowflake cloud-database targeting. After a lull in late 2024, the group resumed operations in 2025 with expanded hybrid-cloud and identity-platform tradecraft, using help-desk impersonation and MFA bypass to obtain administrative access to Okta, AWS, and Microsoft 365/Entra ID tenants.

Unit 42's remediation guidance centers on identity-aware detection engineering rather than patching: correlating identity/authentication telemetry with endpoint, cloud, SaaS, and network telemetry for behavioral context; consolidating that telemetry into a unified investigative platform (Unit 42 references its own Cortex XSIAM); continuously refining detections, correlation rules, and response playbooks for identity-based attack chains; and dedicating resources to proactive threat hunting for credential-abuse patterns specifically (e.g., anomalous MFA re-enrollment, help-desk reset volume, impossible-travel logins).

MITRE ATT&CK techniques used in TL-2026-1938

Credential Access

T1003.006 DCSync; T1539 Steal Web Session Cookie; T1621 Multi-Factor Authentication Request Generation

Lateral Movement

T1021.001 Remote Desktop Protocol

Discovery

T1069.003 Cloud Groups; T1087.004 Cloud Account

Initial Access

T1078.004 Cloud Accounts; T1566.004 Spearphishing Voice

Privilege Escalation

T1098.003 Additional Cloud Roles

Persistence

T1098.005 Device Registration; T1136 Create Account; T1556.006 Multi-Factor Authentication

Collection

T1114.003 Email Forwarding Rule

Defense Evasion

T1564.008 Email Hiding Rules

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Reconnaissance

T1589.001 Credentials

Impact

T1657 Financial Theft

Affected products and versions in Unit 42: Identity Compromise Is the Primary Attack Vector in

  • Okta — Okta Identity Platform
    Vulnerable versions: N/A — identity/process abuse, not a software vulnerability
  • Amazon Web Services — AWS IAM
    Vulnerable versions: N/A — identity/process abuse, not a software vulnerability
  • Microsoft — Microsoft 365 / Entra ID
    Vulnerable versions: N/A — identity/process abuse, not a software vulnerability

Remediation for Unit 42: Identity Compromise Is the Primary Attack Vector in

Patches

  • Not applicable — this threat is identity/process abuse (social engineering, MFA manipulation), not a specific software vulnerability

Immediate actions

  • Require out-of-band, multi-step identity verification before help-desk staff action any password or MFA-method reset request
  • Detect and rate-limit repeated MFA push notifications indicative of MFA fatigue/bombing attacks
  • Correlate identity/authentication telemetry with endpoint, cloud, SaaS, and network telemetry to add behavioral context to logins and MFA events

Workarounds

  • Require phishing-resistant MFA (FIDO2/WebAuthn) for high-privilege and help-desk-resettable accounts to reduce MFA-bombing and SIM-swap bypass risk
  • Restrict help-desk agents' ability to reset MFA/credentials without secondary verification (e.g., manager approval, callback to a pre-registered number, video verification)

Longer-term hardening

  • Consolidate identity, endpoint, cloud, and SaaS telemetry into a unified investigative/correlation platform
  • Dedicate resources to proactive threat hunting for credential-abuse and identity-compromise patterns (anomalous MFA re-enrollment, abnormal help-desk reset volume)
  • Continuously refine detection content, correlation rules, and incident-response playbooks specifically for identity-based, multi-attack-surface intrusion chains

Timeline of Unit 42: Identity Compromise Is the Primary Attack Vector in

  • 0ktapus/0oktapus prebuilt phishing kit emerges, giving Scattered Spider/Muddled Libra a hosted credential-harvesting framework; group begins targeting CRM, BPO, and telecommunications firms
  • Muddled Libra expands targeting beyond telecom/BPO into gaming, hospitality, retail, MSP, manufacturing, and financial-services sectors
  • Muddled Libra joins the ALPHV/BlackCat ransomware-as-a-service affiliate program, adding data-encryption and extortion to its identity-abuse tradecraft
  • CISA and FBI issue joint Cybersecurity Advisory AA23-320A on Scattered Spider TTPs, detailing help-desk social-engineering and MFA-bypass techniques
  • Unit 42 observes a lull in Muddled Libra operational activity in late 2024
  • Unit 42 publishes an updated Threat Group Assessment on Muddled Libra documenting resumed, further-reaching, faster, and more impactful operations
  • CISA and FBI update AA23-320A with new Scattered Spider TTPs, including DragonForce ransomware deployment and targeting of Snowflake cloud databases
  • Unit 42 publishes 'Inside the Modern SOC: The Identity Front Door,' citing Muddled Libra as the exemplar case study for its finding that identity weaknesses factor into ~90% of investigated incidents

Sources cited for Unit 42: Identity Compromise Is the Primary Attack Vector in

Threats related to Unit 42: Identity Compromise Is the Primary Attack Vector in

Detection coverage for TL-2026-1938

As of 2026-08-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1938 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats