Activity timeline
TheHatman appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1621 Multi-Factor Authentication Request Generation — Credential Accessobserved in 3 of 3 tracked threats
- T1069.003 Cloud Groups — Discoveryobserved in 2 of 3 tracked threats
- T1078.004 Cloud Accounts — Initial Accessobserved in 2 of 3 tracked threats
- T1087.004 Cloud Account — Discoveryobserved in 2 of 3 tracked threats
- T1110.003 Password Spraying — Credential Accessobserved in 2 of 3 tracked threats
- T1119 Automated Collection — Collectionobserved in 2 of 3 tracked threats
- T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 3 tracked threats
- T1555 Credentials from Password Stores — Credential Accessobserved in 2 of 3 tracked threats
- T1589.001 Credentials — Reconnaissanceobserved in 2 of 3 tracked threats
- T1650 Acquire Access — Resource Developmentobserved in 2 of 3 tracked threats
- T1069 Permission Groups Discovery — Discoveryobserved in 1 of 3 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 1 of 3 tracked threats
- T1087 Account Discovery — Discoveryobserved in 1 of 3 tracked threats
- T1110 Brute Force — Credential Accessobserved in 1 of 3 tracked threats
- T1213 Data from Information Repositories — Collectionobserved in 1 of 3 tracked threats
Tracked threats
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the ClaimsMEDIUM
- Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCSHIGH
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and OthersHIGH