Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-02

Bling Libra

As of 2026-05-30, Bling Libra is a threat actor tracked by Threadlinqs Intelligence across 5 threats spanning supply chain, data breach, threat actor. ATT&CK coverage spans 78 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1213 (Data from Information Repositories), T1528 (Steal Application Access Token), T1567 (Exfiltration Over Web Service).

Tracked threats
55 high
First seen
2026-02-03
Last seen
2026-04-21
ATT&CK techniques
78across 5 of 5 threats
Related CVEs
0None referenced
5 tracked threat(s) · Categories: SUPPLY_CHAIN, DATA_BREACH, THREAT_ACTOR

Activity timeline

Bling Libra appears in 5 tracked threats between and ; the busiest month was 2026-02 with 3 reports.

ATT&CK techniques observed

78 techniques observed across 5 of 5 tracked threats · Credential Access (14), Resource Development (9), Initial Access (8), Discovery (7), Impact (7), Collection (6)
  • T1213 Data from Information Repositories — Collectionobserved in 5 of 5 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 5 of 5 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 5 of 5 tracked threats
  • T1657 Financial Theft — Impactobserved in 5 of 5 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 4 of 5 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 4 of 5 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 4 of 5 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 4 of 5 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 4 of 5 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 4 of 5 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 4 of 5 tracked threats
  • T1566 Phishing — Initial Accessobserved in 4 of 5 tracked threats
  • T1098.001 Additional Cloud Credentials — Persistenceobserved in 3 of 5 tracked threats
  • T1537 Transfer Data to Cloud Account — Exfiltrationobserved in 3 of 5 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 3 of 5 tracked threats

Tracked threats