Credential abuse techniques – the tactics defenders still miss

0
45
Credential abuse techniques

According to our recent global report, password guessing and valid account misuse rank among the most effective tactics cyber criminals use in 2025. This trend reflects a strategic shift.

Attackers now move away from noisy malware that triggers endpoint protection. Instead, they leverage legitimate access to evade detection.

The Anatomy of a Cyber World is an in-depth global report based on data gathered from Kaspersky Managed Detection and Response (MDR), Incident Response (IR), Compromise Assessment and SOC Consulting in 2025. It covers the most common adversary techniques, tools and detection scenarios. It also highlights the peculiarities of detected incidents.

Credential abuse techniques dominate attack activity

According to the report, a significant portion of the most frequently monitored attack techniques revolves around credentials and identity management. This analysis examines the conversion rates of various Indicators of Attack (IoA).

The report highlights the following prevalent malicious tactics and demonstrates the growing use of credential abuse techniques:

Password guessing – 34.8%

This technique involves attackers systematically trying different passwords until they gain access to an account. It tops the conversion list because it appears in both actual attacks and authorised security assessments. As a result, it remains a persistent threat in today’s cybersecurity landscape.

Organisations that rely on weak or reused passwords continue to enable this age-old strategy. Furthermore, password guessing remains one of the most common credential abuse techniques observed by security teams.

  • Local account creation – 34.7%

Once attackers enter a system, they frequently create new local accounts to maintain access. They can then retain access even if defenders discover and remove the original foothold.

Security teams frequently observe this technique during security exercises. They can also detect it, but only when the right telemetry is in place. Unfortunately, many organisations still lack that visibility.

  • Valid account abuse – 34.5%

Rather than deploying malware, attackers log in with stolen or compromised credentials. They then blend into normal user activity. Consequently, detection becomes significantly more difficult because the access appears legitimate.

The high conversion rate highlights why compromised credentials remain one of the most dangerous attack vectors. It also illustrates why credential abuse techniques continue to deliver strong results for attackers.

  • Account manipulation – 32%

Attackers modify existing accounts to consolidate access. For example, they may activate disabled accounts, alter group memberships or escalate privileges. This tactic reinforces a broader pattern. Rather than introducing new tools, adversaries deepen their control by exploiting existing resources.

  • Network service discovery – 31.2%

Before moving deeper into a network, attackers typically scan for open services and accessible systems. This reconnaissance step strongly predicts what often follows: lateral movement and further exploitation. Therefore, early detection gives security teams a critical opportunity to intervene.

Attackers focus on existing access

The report ranks attacker techniques according to how frequently observed activity ultimately resulted in confirmed malicious incidents. According to our experts, MITRE ATT&CK® catalogues a vast number of adversary techniques. However, effective detection requires organisations to prioritise behaviours with the highest probability of malicious intent. At the same time, they must avoid generating excessive false positives.

Threat actors do not always need sophisticated malware to achieve their objectives. In many cases, legitimate administrative tools and compromised accounts remain the fastest and most effective way to move inside an organisation while avoiding detection.

The continued popularity of these techniques shows that organisations need deep visibility into attacker behaviour and the ability to correlate suspicious activity across different stages of an attack.

Strengthening defences against credential abuse techniques

To address these challenges, companies can enhance their security with our solutions, from threat detection to continuous protection and remediation.

As credential abuse techniques continue to evolve, organisations need stronger visibility into user activity, account behaviour and identity-related threats. Businesses that prioritise detection and response capabilities will be better positioned to identify suspicious activity before attackers can expand their access.


Sergey Soldatov | Head | Security Operations Centre | Kaspersky | mail me |


 



LEAVE A REPLY

Please enter your comment!
Please enter your name here