Activity timeline
T1056.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 14 reports, and 57 of the 58 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1056.003 Web Portal Capture is catalogued by MITRE ATT&CK under the Credential Access and Collection tactics in the Enterprise matrix, as a sub-technique of T1056 Input Capture. Threadlinqs maps 58 of 2623 tracked threats (2.2%) to it; by severity that is 6 critical, 37 high, 15 medium.
Threats that use T1056.003 most often also use T1566.002 Spearphishing Link (40 threats), T1583.001 Domains (36 threats), T1204.001 Malicious Link (32 threats), T1071.001 Web Protocols (28 threats), T1684.001 Impersonation (27 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
27 tracked threat actors appear in the threats that use T1056.003; the most frequent are Ghost Stadium (2), Milk Dragon (2), APT28 (1), APT43 (1), Balonx (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1056.003.
Data sources
Telemetry that can reveal T1056.003, per MITRE ATT&CK.
- File — File Modification
Threat actors using it
Tracked threats
The 30 most recent of 58 tracked threats that use T1056.003.
- Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…high
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)high
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…medium
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Detailsmedium
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flowmedium
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Datahigh
- Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpithigh
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypasscritical
- Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructurehigh
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…high
- HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2high
- Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visitmedium
- AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypasshigh
- Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…critical
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimihigh
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)high
- TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platformsmedium
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Sidehigh
- Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East…high
- Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…high
- GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPshigh
- Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brandsmedium
- Operation RoundPress: TA458 Deploys SpyPress Malware via Half-Click Webmail Zero-Days (CVE-2025-27915…critical
- Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…high
- Google Ads MMC Sync Phishing Campaign Uses Fake Maintenance Notices for Credential Theftmedium
Detection coverage
Threadlinqs maintains 174 detection rules mapped to T1056.003 (SPL 57, KQL 54, Sigma 63). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1056 Input Capture — 285 tracked threats at the technique level.