Skip to main content

Mitigating Large-Scale Credential Attacks and Password Spraying

2 min read Runtime Rebel Intel
Primary source: unit42.paloaltonetworks.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: Enterprises face unauthorized access and data exfiltration via large-scale credential harvesting and password spraying campaigns.
  • Affected systems: Internet-exposed edge devices, Microsoft Entra tenants, and services vulnerable to multi-stage authentication attacks.
  • Remediation: Audit remote access logs for successful logins following high-volume failure events and enforce rigorous edge device hardening.

Advertisement

As modern security perimeters shift toward identity-based access, cybercriminals increasingly rely on logging in rather than breaking in. According to Unit 42, attackers frequently aggregate previously leaked username and password pairs to fuel automated credential attacks against internet-facing infrastructure.

Understanding the Threat Landscape

Recent intelligence highlights a surge in large-scale password spraying and credential stuffing operations targeting various corporate environments. Threat actors utilize curated password lists derived from historical data breaches and newly exploited vulnerabilities to target edge infrastructure, including Fortinet and Sophos devices, alongside Microsoft Entra tenants.

During August 2026, a threat actor operating under the handle “TheHatman” posted offers on cybercrime forums to sell employee data allegedly exfiltrated from corporate Microsoft Entra tenants. While the actor claimed to leverage compromised credentials obtained through MFA fatigue and password spraying, security researchers have noted that exact initial access vectors remain difficult to verify independently. Concurrently, campaigns such as “FortiBleed” have demonstrated how initial access brokers weaponize stolen credentials to pivot across exposed services.

Attack Mechanics and TTPs

Attackers typically execute a multi-stage process to establish persistence and escalate privileges within targeted networks:

  • Credential Gathering: Aggregating leaked credentials from previous breaches and underground forums.
  • Password Spraying: Launching low-and-slow authentication attempts against exposed remote access services to avoid triggering account lockout thresholds.
  • MFA Exploitation: Utilizing prompt fatigue techniques to bypass multi-factor authentication controls.
  • Lateral Movement: Pivoting from compromised edge devices into internal cloud and on-premises environments.

Actionable Recommendations and Mitigations

Defenders must prioritize proactive threat hunting and perimeter hardening to disrupt identity-based campaigns. Organizations should implement the following security measures:

  • Log Analysis: Audit remote access logs specifically for successful logins occurring shortly after high-volume password failure events.
  • Edge Hardening: Review and enforce strict hardening guidelines for all internet-exposed edge devices and VPN gateways.
  • Identity Monitoring: Deploy Identity Threat Detection and Response (ITDR) solutions to identify anomalous access patterns and compromised cloud identities in real-time.
  • MFA Policy Tuning: Implement phishing-resistant multi-factor authentication, such as FIDO2-compliant security keys, to neutralize MFA fatigue tactics.

Related: Identity Attacks & MFA Bypass: The New Ransomware Entry Point, Zero-Click AI Browser Hacking Threatens Claude and ChatGPT Atlas

Advertisement

Advertisement