Abstract illustration of a cluster of translucent hexagonal blocks, violet on the left and cyan on the right, with small padlock icons on circuit lines against dark navy

Attackers Target Service Accounts Overlooked by Zero Trust

Machine identities are an active attack surface that many Zero Trust programs overlook. A CrowdStrike-sponsored analysis published by Dark Reading lays out how adversaries deliberately hijack and impersonate non-human identities: service accounts, API keys, and OAuth tokens.

The appeal is structural. These accounts tend to carry standing privilege, live for years without rotation, and generate little scrutiny, so they slip past the MFA and conditional-access rules built for human logins.

The report details specific incidents. In a January 2024 case, the eCrime group PUNK SPIDER (linked to Akira ransomware) took over a privileged Active Directory service account and used it to pivot across systems over RDP before deploying ransomware. In an early 2025 incident tied to the Iran-linked STATIC KITTEN, operators created a fake account called “servicedesk,” gave it local admin rights, and edited the registry to keep it out of view.

This risk extends to SaaS. The report references stolen CRM OAuth tokens used to pull data out of connected applications, which puts API grants and workload credentials in the same threat model as on-prem accounts. As the sponsored piece puts it, many organizations “lack visibility into what accounts exist and how their privileges change over time.”

Security architects should take these practical steps: inventory every non-human account, cut standing permissions to least privilege, enforce rotation and short-lived credentials, and extend Zero Trust policy to workload and agent identities. Note the source is vendor-commissioned, and the incident details are single-sourced to CrowdStrike.

Source: Dark Reading


Leave a Reply

Discover more from Digerati One (Di1) | AI Integration & Multi-Cloud Architecture

Subscribe now to keep reading and get access to the full archive.

Continue reading