The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door
Not elite. Not cinematic. Just effective, and that's the problem.

Key points
- Phishing is now routed through shared documents, calendar invites, and e-signature services that users were trained to trust.
- Initial access brokers are selling VPN and RDP credentials for three- and low-four-figure sums.
- Session token theft, OAuth abuse, and remote-management tool misuse appear in nearly every mid-market intrusion report this quarter.
- Ransom demands in cases with public reporting ran from the mid-six figures to just under $4 million this week.
- At least two victims appear to have paid, based on leak-site removals.
How did attackers get in this week?
Old credentials that never got rotated opened most of the doors. Incident responders keep finding accounts that survived password resets because session tokens or app passwords weren't revoked. MFA fatigue and adversary-in-the-middle kits, tools that intercept authentication in real time, handle the rest. Microsoft's own guidance on token theft is blunt: assume the cookie is the credential.
Initial access brokers selling this access aren't charging premium rates. Listings on Russian-language forums continue to move VPN and RDP access for three- and low-four-figure sums, with corporate credentials sometimes going for less than a tank of fuel. As we reported on 22 June, underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar further for affiliates who don't want to do their own reconnaissance.
Should you worry about phishing through "safe" channels?
Yes, and the channel is the point. Lures are arriving through shared document notifications, calendar invites, and legitimate e-signature services. The delivery vehicle is whatever the target's security awareness program told users was safe. Email gateways don't see it. Users don't question it. Detection lands on the endpoint, if it lands at all.
What tools are attackers abusing once they're inside?
OAuth consent attacks, malicious Teams messages from compromised tenants, and abuse of legitimate remote-management tools such as ScreenConnect, AnyDesk, and Atera show up in nearly every mid-market intrusion report this quarter. CISA has flagged the remote-management tool pattern repeatedly. Trusted-app abuse is industrialising.
At the browser level, extension-based info-stealers and session hijacking via the browser's own storage are doing what malware once required kernel access to accomplish. The endpoint detection tool doesn't see a suspicious process; it sees Chrome. Our 10 June story on how infostealers became the front door for ransomware gangs laid out why stolen session tokens have reshaped the attack chain, and this week's cases fit that pattern exactly.
Who got hit?
None of the victims were exotic. Manufacturing, regional healthcare, a couple of municipal targets, and the logistics names that show up on Ransomware.live within hours of being posted. The buyers behind these intrusions are affiliates working under ransomware-as-a-service crews. They don't need zero-days, software vulnerabilities no vendor has patched yet, when valid logins are this cheap.
What ties it together is the absence of sophistication. These aren't nation-state operations. They're affiliates with playbooks, working access bought from someone else, hitting organisations whose identity hygiene assumed the bad guys were better resourced than they actually need to be.
The cheap stuff works. That's what this beat keeps proving.



