Emerging Identity Threats: The Muddy Waters of Residential Proxies | Obsidian Security
Thank you for your interest in Obsidian! Please enter your information in the form and we will contact you shortly to schedule a demo. While the goals of various adversary groups may not change drastically over time, their TTPs will. Effective techniques for initial access, post-authentication activity, and dwell time within a target tenant are an attacker’s bread and butter. The cliche of “emerging identity threats” is actually a blurred line between simple IOCs and cutting-edge techniques. In this blog post, we explore the unique aspects of residential proxies in identity phishing attacks. We’ll go over some IOCs you can check in your own environment and cover some strategies for detecting current and new trends in these attacks. In recent weeks, Obsidian observed a set of unique characteristics across several targeted attacks, distinguishing them from others of a similar kind. Phishing kits and services are taking advantage of proxy networks that utilize a variety of residential IPs
Emerging Identity Threats: The Muddy Waters of Residential Proxies AI Security SaaS Security Platform Pricing Resources Company Free trial Get a demo Emerging Identity Threats: The Muddy Waters of Residential Proxies Navigate emerging identity threats from residential proxies. Understand how attackers use legitimate infrastructure to evade detection. Published: May 6, 2024 Updated: November 5, 2025 While the goals of various adversary groups may not change drastically over time, their tactics, techniques, and procedures (TTPs) will. Effective techniques for initial access, post-authentication
Explore this link on the map →related reading
- Shifting detection left for more effective threat detectionpushsecurity.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- Report: Identity Crisis: The Biggest Prize in Security | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- Authenticating AI Agents — Activantactivantcapital.com
- When Intrusions Don’t Align: A New Water Watering Hole and Oldsmar | Dragosdragos.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com