Credential theft remains one of the most persistent vectors of cyberattack because credentials are heterogeneous: different types are stored, stolen, and exploited through distinct mechanisms, yet most defenses are applied uniformly across them. This paper combines a critical review with a targeted design proposal. We first examine how major credential types, including passwords, hashes, Kerberos tickets, cookies, payment-card data, and cryptographic keys, are stored and extracted from memory, disk, and network traffic, and how attackers exploit them once stolen. We then survey existing protection mechanisms, from hardware isolation to FIDO2/WebAuthn, and identify two unresolved gaps in FIDO2: its reliance on a trustworthy browser, and the absence of a cryptographically sound account-recovery mechanism. To address these, we propose an extension combining zero-knowledge browser attestation, built on Direct Anonymous Attestation and TPM-measured platform state, with a Shamir Secret Sharing-based recovery architecture distributed across trusted contacts. We argue, and illustrate through this extension, that credential-specific defenses are more tractable and effective than general-purpose ones.
Baeldung (2024) / Etc / Shadow and Creating Yescrypt, MD5, SHA-256, and SHA-512 Password Hashes. https://www.baeldung.com/linux/shadow-passwords
Microsoft (2025) NTLM user Authentication. https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/ntlm-user-authentication
Microsoft (2025) How to Prevent Windows from Storing a LAN Manager (LM) Hash of the Password in AD and Local SAM Databases. https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/prevent-windows-store-lm-hash-password
Microsoft (2025) NTLM Network Authentication Changes. https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/new-setting-modifies-ntlm-network-authentication
PCI Security Standards Council, LLC (2024) Payment Card Industry Data Security Standard: Requirements and Testing Procedures, Version 4.0.1. Technical Report v4.0.1. https://www.pcisecuritystandards.org/document_library/
Rodríguez, R.J. (2017) Evolution and Characterization of Point-of-Sale RAM Scraping Malware. Journal of Computer Virology and Hacking Techniques , 13, 179-192. https://doi.org/10.1007/s11416-016-0280-4
Kiwia, D., Dehghantanha, A., Choo, K.R. and Slaughter, J. (2018) A Cyber Kill Chain Based Taxonomy of Banking Trojans for Evolutionary Computational Intelligence. Journal of Computational Science , 27, 394-409. https://doi.org/10.1016/j.jocs.2017.10.020
Ah-Fat, P., Huth, M., Mead, R., Burrell, T. and Neil, J. (2020) Effective Detection of Credential Thefts from Windows Memory: Learning Access Behaviours to Local Security Authority Subsystem Service. 23 rd International Symposium on Research in Attacks , Intrusions and Defenses ( RAID 2020 ), San Sebastian, October 2020, 181-194. https://www.usenix.org/system/files/raid20-ah-fat.pdf
Multi-State Information Sharing & Analysis Center (MS-ISAC) (2025) Mimikatz: The Finest in Post-Exploitation, Part 2 in a Series on Malware. https://www.cisecurity.org/insights/blog/mimikatz-the-finest-in-post-exploitation
Huq, N. (2015) Defending against POS RAM Scrapers: Current and Next-Generation Technologies. Technical Report, Trend Micro, Forward-Looking Threat Research Team, White Paper. https://documents.trendmicro.com/assets/wp/wp-defending-against-pos-ram-scrapers.pdf
Dimov, D. and Tzonev, Y. (2017) Pass-the-Hash—One of the Most Prevalent Yet Underrated Attacks for Credentials Theft and Reuse. International Conference on Computer Systems and Technologies ( CompSysTech ’17), Ruse, 23-24 June 2017, 149-154. https://doi.org/10.1145/3134302.3134338
Hans Peter Luhn (1960) Computer for Verifying Numbers. US Patent 2,950,048A. https://patents.google.com/patent/US2950048A/en
Moore, A. (2016) Research Note—Banking Malware Explained: The Case of Dridex. SSRN Working Paper, 7 p. https://doi.org/10.2139/ssrn.2797341
Georgoulias, D., Yaben, R. and Vasilomanolakis, E. (2023) Cheaper than You Thought? A Dive into the Darkweb Market of Cyber-Crime Products. Proceedings of the 18 th International Conference on Availability , Reliability and Security , New York, 29 August 2023-1 September 2023, 1-10. https://doi.org/10.1145/3600160.3605012
Microsoft (2025) Credential Guard Overview. https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/
Microsoft (2025) How Credential Guard Works. https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/how-it-works
Sajid, M.S.I., Ahmed, S. and Sosnoski, R. (2025) Secure Development of a Hooking-Based Deception Framework against Keylogging Techniques. 2025 IEEE Secure Development Conference ( SecDev ), Indianapolis, 14-16 October 2025, 82-91. https://doi.org/10.1109/secdev66745.2025.00019
Sarika Sharma (2025) 5 Ways to Defend against Credential Theft Attacks: A Technical Defense Framework. https://fidelissecurity.com/threatgeek/threat-detection-response/defend-against-credential-theft/
Exabeam (2025) SIEM vs. EDR: Key Features, Differences, and How to Choose. Industry White Paper. https://www.exabeam.com/explainers/siem/siem-vs-edr-key-features-differences-and-how-to-choose/
Keepnet Labs (2025) Understanding and Preventing Credential Theft, 2025. Industry White Paper. https://keepnetlabs.com/blog/understanding-and-preventing-credential-theft
SentinelOne (2025) What Is Endpoint Security? Key Features, Types & Threats. Industry White Paper. https://www.sentinelone.com/cybersecurity-101/endpoint-security/what-is-endpoint-security/
Vectra AI (2025) Endpoint Detection and Response (EDR): The Complete Security Guide. Industry White Paper. https://www.vectra.ai/topics/endpoint-detection-and-response
Palo Alto Networks (2026) What Is Phishing? https://www.paloaltonetworks.com/cyberpedia/what-is-phishing
SentinelOne (2025) What Are Honeytokens in Cybersecurity? https://www.sentinelone.com/cybersecurity-101/cybersecurity/honeytokens/
Acalvio (2025) Understanding Honeytokens: Functions and Different Types. https://www.acalvio.com/resources/glossary/honeytoken/
Huntress (2025) What Is a Honey Token? A Cybersecurity Trap for Catching Intruders. https://www.huntress.com/cybersecurity-101/topic/what-is-honey-token
CrowdStrike (2025) What Are Honeytokens? https://www.crowdstrike.com/en-us/cybersecurity-101/identity-protection/honeytokens/
Shamir, A. (1979) How to Share a Secret. Communications of the ACM , 22, 612-613. https://doi.org/10.1145/359168.359176
Ledger Academy (2023) What Is Shamir’s Secret Sharing? https://www.ledger.com/academy/topics/security/shamirs-secret-sharing
Privy (2026) Sharing the Secret: A Peek under the Hood of Privy’s Shamir Secret Sharing Library. https://privy.io/blog/shamir-secret-sharing-deep-dive
Abidin, A., Aly, A., Mustafa, M.A. (2020) Collaborative Authentication Using Threshold Cryptography. In: Saracino, A. and Mori, P., Eds., Emerging Technologies for Authorization and Authentication , Springer, 122-139. https://doi.org/10.1007/978-3-030-39749-4_8
COSIC (2022) Threshold Crypto and Its Application to Collaborative Authentication. https://www.esat.kuleuven.be/cosic/blog/threshold-crypto-and-its-application-to-collaborative-authentication/
BitGo (2026) What Are Multi-Signature Wallets? Crypto Wallet Security. https://www.bitgo.com/resources/blog/what-is-a-multi-signature-wallet/
Bitcoin Wiki (2025) Multi-Signature. https://en.bitcoin.it/wiki/Multi-signature
Fireblocks (2025) MPC vs. Multi-Sig, October. Industry White Paper. https://www.fireblocks.com/blog/mpc-vs-multi-sig
Cointelegraph (2026) What Is a Multisignature Wallet, and How Does It Work? https://cointelegraph.com/tags/multisignature
Bartock, M., Souppaya, M., Savino, R., Knoll, T., Shetty, U. Cherfaoui, M., et al . (2021) Hardware-Enabled Security: Enabling a Layered Approach to Platform Security for Cloud and Edge Computing Use Cases. NIST Interagency Report NIST IR 8320 (2nd Draft), National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8320
Eskandarian, S., Sethi, T.K., Subbiah, V., Backes, M., Pellegrino, G., Boneh, D., et al . (2019) Fidelius: Protecting User Secrets from Compromised Browsers. 2019 IEEE Symposium on Security and Privacy ( SP ), San Francisco, 19-23 May 2019, 264-280. https://doi.org/10.1109/sp.2019.00036
Michael Waterman (2026) How FIDO2 Works, a Technical Deep Dive. Blog Post Providing Technical Explanation of FIDO2/Webathons Authentication Protocols. https://michaelwaterman.nl/2025/04/02/how-fido2-works-a-technical-deep-dive/
Adam Langley (2019) Zero-Knowledge Attestation. ImperialViolet Blog. https://www.imperialviolet.org/2019/01/01/zkattestation.html
Brickell, E., Camenisch, J. and Chen, L. (2004) Direct Anonymous Attestation. Proceedings of the 11 th ACM Conference on Computer and Communications Security , New York, 11 February 2004, 132-145. https://doi.org/10.1145/1030083.1030103
Yang, K., Chen, L., Zhang, Z., Newton, C.J.P., Yang, B. and Xi, L. (2021) Direct Anonymous Attestation with Optimal TPM Signing Efficiency. IEEE Transactions on Information Forensics and Security , 16, 2260-2275. https://doi.org/10.1109/tifs.2021.3051801
Cloudflare (2022) Introducing Zero-Knowledge Proofs for Private Web Attestation with Cross/Multi-Vendor Hardware. Cloudflare Blog. https://blog.cloudflare.com/introducing-zero-knowledge-proofs-for-private-web-attestation-with-cross-multi-vendor-hardware/
ETSI (2023) Zero Knowledge Proof—European Digital Identity. Technical Report, European Telecommunications Standards Institute. https://www.etsi.org/deliver/etsi_tr/119400_119499/119476/01.02.01_60/tr_119476v010201p.pdf