LmCast :: Stay tuned in

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Recorded: Sept. 10, 2026, 2:09 p.m.

Original Summarized

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Microsoft says September updates fix mouse settings reset issues

CompTIA prep course for 10 certifications is only $17.50 in this deal

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityThe Top 4 Threats We Found by Investigating Every Alert for a Quarter

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Sponsored by Prophet Security

September 10, 2026
10:00 AM
0

Tl;dr: Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked.
Between May 1 and July 31, 2026, Prophet Security investigated every alert in customer environments immediately upon arrival. This removes a common blind spot in threat datasets: the human analyst's decision about which alerts deserve a full investigation.
Of the completed investigations, about 93% were benign and 7% were confirmed malicious. The findings below come from that 7%. They are based on 4.7 million questions asked of customer environments over the quarter, with a median of 35 questions per investigation. Prophet Security published the full dataset in its first quarterly threat report.

Figure 1: The malicious activity our AI SOC analyst identified
One key finding stands out: identity was the target in roughly half of all confirmed malicious activity this quarter. The strongest predictor of a successful account takeover was whether the attacker used a password or an already-authenticated session. This was true for both direct attacks on accounts and phishing campaigns. 
Here are the four patterns we observed:
1. Session hijacking was the top way attackers broke into accounts
Direct attacks on accounts and sessions made up about 18% of confirmed malicious activity. These included session hijacking, token replay, MFA bypass, credential stuffing, and post-compromise persistence using inbox rules and OAuth consent grants. The main factor predicting success was the authentication method the attacker used.
Attempts using a password were usually blocked. For example, conditional access blocked correct passwords coming from commercial VPNs in new countries or unfamiliar hosting providers. Phishing-resistant MFA stopped adversary-in-the-middle proxies that captured credentials. The security controls worked as intended.
However, attempts using an already-authenticated session succeeded repeatedly. In some cases, individual accounts had dozens of malicious sign-ins over three weeks, giving attackers continuous access to emails. The reason is simple: standard conditional access checks during authentication.
Since a replayed session cookie skips authentication, no policy is triggered. A refresh token only returns to the identity provider when redeemed, which is the only time to re-evaluate and revoke access.
While passwords hit security controls, authenticated sessions bypassed them completely.

Figure 2: Stolen, already authenticated sessions bypass typical security controls
This led to two common outcomes. First, disabling the account didn't always stop the attacker. At two organizations, attackers continued using access granted before the account was disabled.
In one case, they even changed authentication methods and granted OAuth consents while the security team thought the incident was closed. Second, when credentials were phished instead of sessions being stolen, the timing revealed relay infrastructure.
For example, a login from one country was followed by an MFA approval from another country just sixteen seconds later, and again after 118 seconds on a second attempt. Such a short gap between countries indicates a real-time proxy intercepting and relaying credentials and approvals.
MFA fatigue attacks also succeeded when allowed by the system. One attacker sent repeated prompts from a residential proxy until the user approved. Another used a combination of brute force, lockout, automatic unlock, and push bombing to register a new device, exploiting the automatic unlock policy.

The Prophet Security Quarterly Threat Report
The Prophet Security Quarterly Threat Report details a complete account takeover, from the initial login to the artifact that bypassed a password reset.
It also includes hardening recommendations for these threats.
Get the Full Report

2. Infostealers delivered via browsers were the primary source of stolen sessions
Malicious code execution and tooling accounted for about 23% of confirmed malicious activity. Overall, infostealer activity affected roughly a quarter of the investigated organizations.
These infostealers were mostly delivered through web browsers, not emails. Attackers used compromised legitimate websites, malicious ads, sponsored search results, and fake CAPTCHA gates (known as ClickFix) that bypass automated sandboxing by requiring a human click. Fake update prompts hosted on compromised sites were frequently seen across multiple organizations.
Attackers often lured users with software they wanted. Trojanized installers were the most common initial foothold, found at about a quarter of organizations. For example, a trojanized version of a popular AI application ran from a downloads folder, disabled Windows Defender, set up a highly privileged scheduled task, and opened command-and-control channels.
Similar techniques were used to hide malware in hardware diagnostic tools, public code packages, screenshot utilities, cracked software, and remote-support tools.
We identified delivery tools like ClearFake and SocGholish, and payloads including Lumma Stealer, Vidar, HijackLoader, and AsyncRAT.
While SocGholish infrastructure was disrupted on June 18, 2026 under Operation Endgame (during our reporting period), its fake update model continues to be used by ClearFake and other groups, showing that the technique survives even when the operators are shut down.
These stolen sessions often come from the browser's cookie store. In one case, a script decrypted the browser's cookie store, extracted Microsoft authentication cookies, and used them to make authenticated API requests. This is how attackers get the session cookies they replay to bypass security.
A stolen cookie requires no password or MFA, and it survives a password reset or even a device wipe if the session isn't revoked. Ultimately, an endpoint compromise quickly becomes an identity compromise through the browser.
3. Phishing attacks were highly targeted
Credential phishing made up about 28% of confirmed malicious activity, making it the largest single category. These attacks primarily aimed to steal credentials or sessions rather than deliver malware.
These campaigns were highly targeted, often hitting the same people repeatedly. For example, one finance executive faced dozens of different phishing campaigns over three months. Another recipient was targeted for months, while someone else received near-identical phishing emails from different domains twice in two weeks.

Figure 3: These campaigns often hit the same people (often in financial roles) repeatedly
Attackers focused on financial roles: finance executives, collections, accounts payable, treasury mailboxes, and company leaders receiving ACH-themed lures. In one instance, they targeted an automated invoice-processing mailbox, which lacks a human user to spot suspicious activity.
The phishing emails often came from trusted infrastructure, such as legitimate collaboration platforms, major cloud email services, and consumer file-sharing links. Some messages impersonated internal systems like calendar services. Attackers used modern tactics: Unicode characters in subject lines to evade filters, newly registered domains, typosquatted domains, and tracking pixels to verify when an email was opened.
Standard email authentication checks weren't always effective. In one case, a spoofed message that failed SPF, DKIM, and DMARC still reached over a dozen inboxes. The time it took to remove malicious emails varied from seconds to over a day.
Organizations with automated remediation removed emails in seconds. Without it, a CEO impersonation lure sat in a finance director's inbox for nearly a full workday.
Once attackers gained access, they used mailbox rules to stay hidden. Modifying inbox rules was extremely common, seen at nearly as many organizations as impossible travel alerts. Attackers create rules to delete or hide incoming emails so the victim doesn't see their replies. This simple persistence method survives a password reset and remains highly effective.
4. The longest intrusions occurred on unmonitored assets
Pre-ransomware and manual attacker activity made up about 9% of confirmed malicious activity. EDR was the broadest telemetry source behind these findings, and that volume is why investigating EDR alerts at depth is expensive. Most of this activity occurred on devices where no endpoint agent was installed at all.
For example, a multi-week credential attack targeted a production identity server lacking endpoint coverage. In another case, a six-week lateral movement campaign started from an unmanaged, unmonitored host. Several long-running intrusions were only detected because of telemetry from other network devices, as the attackers' machines were entirely unmonitored.
When credential access was detected, it often involved legitimate Windows tools. Attackers used accessibility utilities, task manager, and error reporting services to access the Local Security Authority Subsystem Service (LSASS).
Other attackers bypassed LSASS, creating shadow copies to read credential data from the registry or using a legitimate remote registry service with an impersonation token.
Pre-ransomware activities such as destroying shadow copies, dumping credentials, and deploying remote access tools were much more common than actual ransomware deployment. In two instances, the attacks were stopped while they were still in progress.
About 15% of organizations had attackers using commercial remote access tools to maintain access. Attackers used consumer remote desktop software and remote support tools, which evade malware controls because they are legitimate applications. This access also survives a password reset.
Comparing endpoint agent coverage to authentication logs (instead of just the asset inventory) revealed unmonitored machines authenticating to the network. Two of the quarter's longest-running campaigns operated from these unmonitored devices.
Summary of the quarter
Most of the confirmed attacks this quarter relied on well-known methods: stolen session cookies, MFA push bombing, fake software installers, and using publicly breached credentials. The only truly novel event was an AI agent running a complete intrusion, which began during a model evaluation with safety settings turned off and was eventually caught by another company's security team.
The attack techniques haven't changed much. Instead, attackers are simply bypassing existing security controls. When authentication became stronger, attackers started stealing active sessions. As malware detection improved, they began tricking users into approving fake installers.
This requires no innovation on the attacker's side, only attention to where each control stops.
Three of our four findings share a critical trait: the attacker's access survives a password reset. Stolen session cookies, hidden inbox rules, and persistent remote-support tools all bypass a simple password change. Incident response plans that stop at resetting a password leave the attacker inside the network, as two organizations in this dataset discovered.
Each case was ultimately resolved by asking basic questions and finding the answers: Has this account signed in from here before? Was MFA actually completed? Is this user a developer? Has this sender reached this recipient before? Answering these questions takes time. Often, they go unasked because analysts have to prioritize hundreds of other alerts.
About the data
These findings are based on investigations completed by the Prophet AI SOC Analyst between May 1 and July 31, 2026.
The category percentages represent shares of confirmed malicious investigations and are rounded. Authorized penetration tests and red team exercises were marked as benign and excluded from the malicious data. We do not publish identifying details, per-organization counts, or industry breakdowns.
Prophet Security is a leading agentic AI SOC platform, recognized in Rising in Cyber 2026 on a vote of more than 150 CISOs and security leaders. Its AI SOC analyst investigates every alert across endpoint, identity, email, cloud, and network telemetry and records the evidence behind each determination.
Read the full Quarterly Threat Report to see all four findings in depth, get hardening recommendations, and walk through a step-by-step reconstruction of an account takeover.
Sponsored and written by Prophet Security.

Cybersecurity
Infostealer
Phishing
Prophet Security
Session Hijack
Threat Report
Umonitored Asset

Previous Article

Comments have been disabled for this article.

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

Overdue a password health-check? Audit your Active Directory for free

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Prophet Security investigated every alert across customer environments between May 1 and July 31, 2026, to identify the top four threat patterns, finding that identity was the target in approximately half of all confirmed malicious activity. The investigation processed approximately 4.7 million questions, with a median of 35 questions per inquiry, and ultimately confirmed malicious activity accounted for only 7% of the total investigations.

The first observed pattern involved session hijacking, which constituted about eighteen percent of confirmed malicious activity, including session hijacking, token replay, MFA bypass, credential stuffing, and post-compromise persistence via inbox rules and OAuth consent grants. The success of these attacks was critically dependent on the authentication method used by the adversary. While attempts using traditional passwords were often successfully blocked by security controls such as conditional access policies targeting logins from commercial VPNs or unfamiliar hosting providers, already authenticated sessions repeatedly bypassed these controls. Stolen session cookies allowed attackers to replay session data without triggering standard authentication checks, as refresh tokens are only re-evaluated upon redemption. This finding demonstrated that authenticated sessions provided a direct path for attackers to maintain access, sometimes resulting in dozens of malicious sign-ins over a few weeks, particularly when standard security measures failed to account for session state. Furthermore, techniques like MFA fatigue and exploiting automatic unlock policies through brute force and push bombing were successful against users.

The second major pattern identified was the delivery of infostealers through web browsers, which accounted for about twenty-three percent of confirmed malicious activity, impacting roughly a quarter of the investigated organizations. Attackers predominantly delivered malicious code via web browsers, utilizing compromised legitimate websites, malicious advertisements, sponsored search results, and fake Captcha gates known as ClickFix to bypass automated sandboxing. Initial system footholds were often established through trojanized installers, frequently originating from downloads folders, which were used to disable endpoint protection software, deploy scheduled tasks, and establish command and control channels. These techniques were adapted to hide malware within various legitimate tools, including hardware diagnostic utilities, screenshot utilities, and remote-support software, often involving payloads such as Lumma Stealer or AsyncRAT. Stolen sessions were frequently derived from the browser's cookie store; in some cases, scripts successfully decrypted this store to extract Microsoft authentication cookies, which attackers then replayed to execute authenticated API requests, thereby bypassing the need for passwords or multi-factor authentication.

Third, credential phishing emerged as the largest category of malicious activity, responsible for twenty-eight percent of confirmed incidents. These phishing campaigns were highly targeted, frequently aiming at individuals in financial roles, such as executives, treasury personnel, and accounts payable staff, often using lures related to ACH transactions. Attackers leveraged trusted infrastructure, including legitimate collaboration platforms and major cloud email services, and employed sophisticated evasion tactics like Unicode characters in subject lines, typosquatted domains, and tracking pixels. Although standard email authentication checks like SPF, DKIM, and DMARC were sometimes evaded, the persistence mechanism proved highly effective; attackers commonly modified mailbox rules to hide incoming emails, a persistence method that remains effective even after a password reset.

The fourth pattern involved the longest-running intrusions, representing about nine percent of confirmed malicious activity, and primarily focused on unmonitored assets. These protracted intrusions demonstrated that long-running campaigns often originated from hosts where no endpoint agent was installed, leading to a complete lack of endpoint coverage. Attackers leveraged legitimate Windows tools, such as accessibility utilities and task manager, to access sensitive system memory areas like the Local Security Authority Subsystem Service (LSASS), or they created shadow copies to extract credential data from the registry. Moreover, attackers often used commercial remote access tools, such as consumer remote desktop software, to maintain persistence, as these tools evade typical malware detection controls, and this access persisted even following password changes. The observation that unmonitored machines were authenticating to the network provided the telemetry necessary to detect these undetected, long-running activities.

Overall, the analysis indicated that attack methodologies have not fundamentally changed; instead, adversaries focus on bypassing existing security controls. A critical shared characteristic across most findings was that access successfully survived a password reset, whether through the use of stolen session cookies, the creation of hidden inbox rules, or the deployment of persistent remote-support tools. Effective incident response requires moving beyond simple password resets to investigate the context of access by analyzing whether the login originated from a known location, if MFA was truly completed, and if the user context aligns with the activity, necessitating a deeper, time-consuming analysis of security telemetry.