Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents
Unit 42: Identity Compromise Is the Primary Attack Vector in (TL-2026-1938) is a high-severity tracked intrusion set, first published 2026-08-08. It is attributed to Scattered Spider with high confidence, affects Okta Okta Identity Platform, maps to 17 MITRE ATT&CK techniques (T1003.006, T1021.001, T1069.003), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-1938
- Threat ID
- TL-2026-1938
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-08-08
- Last reviewed
- 2026-08-08
- Attribution
- Scattered Spider
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- technology, business process outsourcing, telecoms, hospitality, financial services, gaming, retail, managed service providers, manufacturing
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Unit 42: Identity Compromise Is the Primary Attack Vector in
Malware and tooling: ALPHV/BlackCat, AnyDesk, DragonForce, MimiKatz, Raccoon Stealer - S1148, SharpHound, TeamViewer, 0ktapus phishing kit, AnyDesk, ConnectWise ScreenConnect, Mimikatz, RSocx
Unit 42's 'Inside the Modern SOC: The Identity Front Door' report finds identity weaknesses played a role in nearly 90% of investigated incidents, with 65% of initial access activity involving identity-based techniques and 87% of incidents spanning multiple attack surfaces. The report cites Muddled Libra (Scattered Spider) as the exemplar of identity-abuse tradecraft: help-desk impersonation, MFA fatigue/bypass, and social engineering to defeat traditional perimeter controls.
How Unit 42: Identity Compromise Is the Primary Attack Vector in works
Palo Alto Networks Unit 42 published 'Inside the Modern SOC: The Identity Front Door' on 2026-08-07 (author Sharon Maydar), synthesizing incident-response findings across Unit 42's investigated caseload. The headline findings: identity weaknesses factored into roughly 90% of incidents investigated; 65% of initial-access activity specifically involved identity-based techniques (credential theft, MFA manipulation, session hijacking, and social engineering); and 87% of incidents spanned multiple attack surfaces (endpoint, cloud, SaaS, and network) rather than staying contained to a single domain. Unit 42 describes a repeatable attack progression: initial identity compromise, followed by persistence and account expansion, privilege escalation, multi-domain lateral movement, and finally objective achievement — ransomware deployment, data theft, financial fraud, or long-term persistent access.
The report cites Muddled Libra (publicly tracked as Scattered Spider, UNC3944, Octo Tempest, and Storm-0875) as the clearest example of this identity-first tradecraft. Muddled Libra is a native-English-speaking, financially motivated cybercrime group active since at least 2022. Rather than exploiting software vulnerabilities, the group's signature technique is social-engineering help-desk and IT-support staff by phone or SMS: callers impersonate a locked-out employee, pressure the agent into resetting the target's password and/or MFA method, and then enroll an attacker-controlled device for future MFA approvals. Where help-desk impersonation is not viable, the group instead floods a target with repeated MFA push notifications ('MFA fatigue' / MFA bombing) until the victim approves one out of frustration. Unit 42 has documented cases where this chain took the group from initial contact to domain administrator rights in under 40 minutes without deploying any malware.
Muddled Libra emerged from the 0oktapus/0ktapus phishing-kit ecosystem in 2022, initially targeting CRM, business-process-outsourcing (BPO), and telecommunications firms before expanding in 2023 into gaming, hospitality, retail, MSP, manufacturing, and financial-services targets. In 2023 the group joined the ALPHV/BlackCat ransomware-as-a-service affiliate program; a joint CISA/FBI advisory (AA23-320A) was first issued 2023-11-16 and substantially updated 2025-07-29 to document new tradecraft including DragonForce ransomware deployment and Snowflake cloud-database targeting. After a lull in late 2024, the group resumed operations in 2025 with expanded hybrid-cloud and identity-platform tradecraft, using help-desk impersonation and MFA bypass to obtain administrative access to Okta, AWS, and Microsoft 365/Entra ID tenants.
Unit 42's remediation guidance centers on identity-aware detection engineering rather than patching: correlating identity/authentication telemetry with endpoint, cloud, SaaS, and network telemetry for behavioral context; consolidating that telemetry into a unified investigative platform (Unit 42 references its own Cortex XSIAM); continuously refining detections, correlation rules, and response playbooks for identity-based attack chains; and dedicating resources to proactive threat hunting for credential-abuse patterns specifically (e.g., anomalous MFA re-enrollment, help-desk reset volume, impossible-travel logins).
MITRE ATT&CK techniques used in TL-2026-1938
Credential Access
T1003.006 DCSync; T1539 Steal Web Session Cookie; T1621 Multi-Factor Authentication Request Generation
Lateral Movement
T1021.001 Remote Desktop Protocol
Discovery
T1069.003 Cloud Groups; T1087.004 Cloud Account
Initial Access
T1078.004 Cloud Accounts; T1566.004 Spearphishing Voice
Privilege Escalation
T1098.003 Additional Cloud Roles
Persistence
T1098.005 Device Registration; T1136 Create Account; T1556.006 Multi-Factor Authentication
Collection
T1114.003 Email Forwarding Rule
Defense Evasion
Exfiltration
T1567.002 Exfiltration to Cloud Storage
Reconnaissance
Impact
Affected products and versions in Unit 42: Identity Compromise Is the Primary Attack Vector in
- Okta — Okta Identity Platform
Vulnerable versions: N/A — identity/process abuse, not a software vulnerability - Amazon Web Services — AWS IAM
Vulnerable versions: N/A — identity/process abuse, not a software vulnerability - Microsoft — Microsoft 365 / Entra ID
Vulnerable versions: N/A — identity/process abuse, not a software vulnerability
Remediation for Unit 42: Identity Compromise Is the Primary Attack Vector in
Patches
- Not applicable — this threat is identity/process abuse (social engineering, MFA manipulation), not a specific software vulnerability
Immediate actions
- Require out-of-band, multi-step identity verification before help-desk staff action any password or MFA-method reset request
- Detect and rate-limit repeated MFA push notifications indicative of MFA fatigue/bombing attacks
- Correlate identity/authentication telemetry with endpoint, cloud, SaaS, and network telemetry to add behavioral context to logins and MFA events
Workarounds
- Require phishing-resistant MFA (FIDO2/WebAuthn) for high-privilege and help-desk-resettable accounts to reduce MFA-bombing and SIM-swap bypass risk
- Restrict help-desk agents' ability to reset MFA/credentials without secondary verification (e.g., manager approval, callback to a pre-registered number, video verification)
Longer-term hardening
- Consolidate identity, endpoint, cloud, and SaaS telemetry into a unified investigative/correlation platform
- Dedicate resources to proactive threat hunting for credential-abuse and identity-compromise patterns (anomalous MFA re-enrollment, abnormal help-desk reset volume)
- Continuously refine detection content, correlation rules, and incident-response playbooks specifically for identity-based, multi-attack-surface intrusion chains
Timeline of Unit 42: Identity Compromise Is the Primary Attack Vector in
- 0ktapus/0oktapus prebuilt phishing kit emerges, giving Scattered Spider/Muddled Libra a hosted credential-harvesting framework; group begins targeting CRM, BPO, and telecommunications firms
- Muddled Libra expands targeting beyond telecom/BPO into gaming, hospitality, retail, MSP, manufacturing, and financial-services sectors
- Muddled Libra joins the ALPHV/BlackCat ransomware-as-a-service affiliate program, adding data-encryption and extortion to its identity-abuse tradecraft
- CISA and FBI issue joint Cybersecurity Advisory AA23-320A on Scattered Spider TTPs, detailing help-desk social-engineering and MFA-bypass techniques
- Unit 42 observes a lull in Muddled Libra operational activity in late 2024
- Unit 42 publishes an updated Threat Group Assessment on Muddled Libra documenting resumed, further-reaching, faster, and more impactful operations
- CISA and FBI update AA23-320A with new Scattered Spider TTPs, including DragonForce ransomware deployment and targeting of Snowflake cloud databases
- Unit 42 publishes 'Inside the Modern SOC: The Identity Front Door,' citing Muddled Libra as the exemplar case study for its finding that identity weaknesses factor into ~90% of investigated incidents
Sources cited for Unit 42: Identity Compromise Is the Primary Attack Vector in
- Inside the Modern SOC: The Identity Front Door
- #StopRansomware: Scattered Spider (AA23-320A, updated)
- Scattered Spider Cybersecurity Advisory AA23-320A (original PDF)
- Scattered Spider, Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944 (Group G1015)
- Threat Group Assessment: Muddled Libra (Updated May 16, 2025)
- Cybersecurity Alert - FINRA Notifies Members of Joint CISA & FBI Cybersecurity Advisory (AA23-320A)
Threats related to Unit 42: Identity Compromise Is the Primary Attack Vector in
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
- Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecraft
- Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others
Detection coverage for TL-2026-1938
As of 2026-08-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1938 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.