A new report by IBM reveals that identity theft has become the top attack vector enabling cybercrime globally. IBM's 2024 X-Force Threat Intelligence Index highlights that abuse of stolen credentials surged last year. The identity crisis magnified response time and impacts of security incidents.

Key findings from the report include the following:

  • Abuse of valid accounts rose 71% year-over-year, now representing 30% of initial access vectors
  • Breaches involving compromised credentials required 190% more effort to remediate than average.
  • Data theft and leak incidents rose to 32% of cases, surpassing extortion as the top impact
  • Infostealer malware activity increased 266%
  • Security misconfigurations accounted for 30% of web application vulnerabilities identified

“The biggest surprise to us was how much of a growth we saw in identity-related attacks,” Michelle Alvarez, strategic threat analysis manager at IBM X-Force, told SDxCentral. “While we anticipated the use of valid credentials to land in the top three initial access vectors, we did not expect it to tie with phishing nor for there to have been such a significant increase in volume of these attacks year-over-year (71%).”

Why identity attacks are surging

The report shows a major shift towards attackers abusing stolen credentials and exploiting identity. There are several reasons why this shift is occurring.

Alvarez said that enterprises are getting better at recognizing phishing campaigns and implementing patch-management, forcing attackers to shift to other methods for initial compromise. Meanwhile, there are already billions of credentials available right now on the dark web, so it's less resource-intensive and more cost effective and stealthier for attackers to log in versus hacking in. She noted that the main challenge for organizations is identifying legitimate traffic vs malicious when an attacker logs in using valid credentials.

What's also happening is there has been a 266% year-over-year increase in the use of infostealers.

“Attackers are investing in malware that steals credentials, in addition to other sensitive and confidential data, thus adding to the pool of compromised credentials,” Alvarez said. “Organizations need to get proactive and get a handle on their dark web exposure, to know if there are any at-risk credentials and session keys that are out there readily available to attackers.”

Beware of ‘kerberoasting’ attacks that steal identity

One particular type of attack is growing is something that IBM refers to as  kerberoasting.

Kerberos is a widely used authentication protocol that is commonly used in Microsoft Active Directory environments. Active Directory is often the lynchpin of enterprise identity, providing identity and access management to applications. Kerberoasting is an attack where threat actors request tickets for service accounts from the Kerberos authentication system and then crack the passwords offline to gain access to privileged accounts across a network. IBM observed a 100% increase in kerberoasting attacks in 2023 as attackers increasingly target identity services to move laterally.

As Kerberos is a legitimate system the attacks are often difficult for organization to detect. Alvarez commented that there are many possible mitigations or best practices to addressing kerberoasting attacks. Some of the top ones to focus on are configuring shorter timelines for kerberos ticket policies, disabling unnecessary server principal names, and enabling advanced encryption standard (AES(.

“When it comes to kerberos ticket policies, organizations should configure these to have shorter lifetimes, reducing the window of time an attacker has to crack the encrypted part of the ticket,” she said.

Additionally, Alvarez recommends that organizations should also review and remove unnecessary Server Principal Names (SPN) that are registered in the environment, as each SPN can potentially be targeted by a kerberoasting attack. Another factor that can have a big impact is using AES encryption for kerberos tickets, as AES is more secure and less susceptible to certain types of attacks compared to older encryption types like RC4.

Is it time to worry about generative AI?

While generative artificial intelligence was the most hyped technology of 2023, IBM X-Force isn't seeing AI as a major threat – quite yet.

One of the areas where some security reports have called out AI risk is from phishing, where AI is able to craft more articulate messages to lure unsuspecting victims. But that's not the view that IBM holds.

“In 2023, we saw a 44% drop in compromises through phishing,” Alvarez said. “This is likely a reflection of both continued adoption and revaluation of phishing mitigation techniques and strategies.”

Alvarez noted that while there is concern that AI-generated phishes could potentially be more deceitful, these same phishing mitigation techniques and strategies should reduce risk of compromise through phishing – even if it's AI-generated.

In terms of email threats, she said that more concerning are the threats that may not beireceiving the same amount of attention, such as cases involving email compromises that circumvented multifactor authentication (MFA measures using adversary-in-the-middle (AitM) attacks.

“X-Force responded to multiple incidents last year where these attacks started with an initial phishing message that directed users to a reverse-proxy phishing page, which allowed attackers to relay traffic between the user and the legitimate site and thus collect user credentials, MFA input and session cookies,” she said.

Looking forward, Alvarez expects that the use of valid accounts will still be one of the top ways that attackers gain initial access in the coming year. Her hope is that  by shining a light on this issue now,  the volume of these attacks year over year shrinks and IBM will be able to report a decrease in attacks as a result of this method. AI is also likely to be a much bigger concern.

“I also anticipate we'll have a lot more to say on AI-engineered cybercriminal campaigns, and will be reporting on increases in threat actors leveraging AI in their operations,” she said.