INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Exploits Cloud Credentials to Steal User Identities
| 2026-07-28 21:33 DATA BREACH
Executive Summary
AI-generated
A potentially larger identity problem was exposed last year when a small, isolated cloud account triggered an anomaly investigation. Aleksandr Krasnov discovered a mesh of "ghost credentials" and nonhuman identities (NHIs) that lived outside traditional trust boundaries but were still able to move laterally through the environment and escalate privileges. The attack works by exploiting dormant permissions in AI-enabled workflow agents, allowing attackers to pivot into identity providers such as Okta within just five minutes. As a result of this incident, Krasnov plans to outline a red-team methodology for turning a single leaked key into a full cloud compromise at Black Hat USA 2026. The affected organizations are likely smaller and midsize companies with up to 2,000 employees, which can realistically take six to nine months to clean up their NHI trust graph using the open-source tool NHI Hound developed by Krasnov.
Technical Mitigations AI-generated
• Use NHI Hound to ingest identity data from providers such as Okta, GitHub, and cloud IAM platforms.
• Block or hunt for exposed tokens using techniques like those described by Aleksandr Krasnov in his research on ghost credentials.
• Regularly update and patch systems against known vulnerabilities, including the use of Okta's security patches to prevent identity provider admin role escalation.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Tactical Metrics
Intelligence Sources
Dark Reading
2026-07-28