Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-08

TheHatman

As of 2026-08-17, TheHatman is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning data breach. ATT&CK coverage spans 22 techniques across 10 tactics in 3 of 3 tracked threats. Most-observed techniques: T1621 (Multi-Factor Authentication Request Generation), T1069.003 (Cloud Groups), T1078.004 (Cloud Accounts).

Tracked threats
32 high · 1 medium
First seen
2026-08-16
Last seen
2026-08-17
ATT&CK techniques
22across 3 of 3 threats
Related CVEs
0None referenced
3 tracked threat(s) · Categories: DATA_BREACH

Activity timeline

TheHatman appears in 3 tracked threats between and .

ATT&CK techniques observed

22 techniques observed across 3 of 3 tracked threats · Credential Access (6), Discovery (4), Initial Access (3), Collection (2), Lateral Movement (2), Reconnaissance (2)
  • T1621 Multi-Factor Authentication Request Generation — Credential Accessobserved in 3 of 3 tracked threats
  • T1069.003 Cloud Groups — Discoveryobserved in 2 of 3 tracked threats
  • T1078.004 Cloud Accounts — Initial Accessobserved in 2 of 3 tracked threats
  • T1087.004 Cloud Account — Discoveryobserved in 2 of 3 tracked threats
  • T1110.003 Password Spraying — Credential Accessobserved in 2 of 3 tracked threats
  • T1119 Automated Collection — Collectionobserved in 2 of 3 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 3 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 2 of 3 tracked threats
  • T1589.001 Credentials — Reconnaissanceobserved in 2 of 3 tracked threats
  • T1650 Acquire Access — Resource Developmentobserved in 2 of 3 tracked threats
  • T1069 Permission Groups Discovery — Discoveryobserved in 1 of 3 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 1 of 3 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 1 of 3 tracked threats
  • T1110 Brute Force — Credential Accessobserved in 1 of 3 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 1 of 3 tracked threats

Tracked threats