The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door

Not elite. Not cinematic. Just effective — and that's the problem.

ThreatVectr Newsdesk· 2 min read
The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door
Share

The criminal ecosystem had another loud week, and almost none of it required talent.

The pattern that keeps surfacing on response calls and leak-site chatter is the same: old credentials that never got rotated, trusted SaaS apps abused for staging, browser-level tricks bypassing controls that assumed the network perimeter still meant something, and phishing routed through workflows users were trained to trust.

That last bit is the one worth dwelling on.

Phishing is no longer arriving only through email. Operators are piping lures through shared document notifications, calendar invites, ticketing platforms, and increasingly through legitimate marketing and e-signature services. The delivery vehicle is whatever the target's security awareness program told them was safe. Email gateways don't see it. Users don't question it. Detection lands on the endpoint, if it lands at all.

The initial access brokers selling this stuff aren't charging premium rates. Listings on the usual Russian-language forums continue to move VPN and RDP access for three- and low-four-figure sums, with corporate credentials sometimes going for less than a tank of fuel. The buyers — affiliates working under RaaS crews — don't need zero-days when valid logins are this cheap.

A few threads worth tracking:

Credential reuse is still the dominant story. Incident responders keep finding accounts that survived password resets because session tokens or app passwords weren't revoked. MFA fatigue and adversary-in-the-middle kits handle the rest. Microsoft's own guidance on token theft is blunt about it: assume the cookie is the credential.

Trusted-app abuse is industrialising. OAuth consent attacks, malicious Teams messages from compromised tenants, and abuse of legitimate remote-management tools (ScreenConnect, AnyDesk, Atera) show up in nearly every mid-market intrusion report this quarter. CISA has flagged the RMM pattern repeatedly.

Browser is the new endpoint. Extension-based info-stealers, malicious profile sync, and session hijacking via the browser's own storage are doing what malware used to require kernel access for. The EDR doesn't see a process; it sees Chrome.

None of the victims this week were exotic. Manufacturing, regional healthcare, a couple of municipal targets, and the usual logistics names that show up on Ransomware.live within hours of being posted. Ransom demands in the cases with public reporting ranged from the mid-six figures to just under $4 million. At least two victims appear to have paid based on leak-site removals. The rest are still listed.

What ties it together is the lack of sophistication. These aren't APT operations. They're affiliates with playbooks, working access bought from someone else, hitting organisations whose identity hygiene assumed the bad guys were better resourced than they actually need to be.

The cheap stuff works. That's the headline.

© 2026 Threat Vectr