# T1056.003 Web Portal Capture

> As of 2026-10-05, T1056.003 (Web Portal Capture) appears in 58 tracked threats, first reported 2021-11-25 and most recently 2026-10-04, with linked actors including Ghost Stadium, Milk Dragon, APT28; it most often appears alongside T1566.002 (Spearphishing Link).

- **Tracked threats:** 58 (6 critical, 37 high, 15 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-04
- **Threat actors:** 27
- **Detection rules:** 174 (counts only; Blue tier and above)

## Key facts

- **ID:** T1056.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access, Collection
- **Matrix:** Enterprise
- **Parent:** T1056
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1056/003/

## Activity timeline

T1056.003 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 14 reports, and 57 of the 58 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1056.003 Web Portal Capture is catalogued by MITRE ATT&CK under the Credential Access and Collection tactics in the Enterprise matrix, as a sub-technique of [T1056 Input Capture](https://intel.threadlinqs.com/technique/T1056). Threadlinqs maps 58 of 2623 tracked threats (2.2%) to it; by severity that is 6 critical, 37 high, 15 medium.

Threats that use T1056.003 most often also use [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (40 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (36 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (32 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (28 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (27 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

27 tracked threat actors appear in the threats that use T1056.003; the most frequent are [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) (2), [Milk Dragon](https://intel.threadlinqs.com/actor/Milk%20Dragon) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [Balonx](https://intel.threadlinqs.com/actor/Balonx) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1056.003.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)

## Data sources

Telemetry that can reveal T1056.003, per MITRE ATT&CK.

- File — File Modification

## Threat actors using it

- [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) — 2
- [Milk Dragon](https://intel.threadlinqs.com/actor/Milk%20Dragon) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Balonx](https://intel.threadlinqs.com/actor/Balonx) — 1
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 1
- [DarkSpectre](https://intel.threadlinqs.com/actor/DarkSpectre) — 1
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [Magecart](https://intel.threadlinqs.com/actor/Magecart) — 1
- [Outsider](https://intel.threadlinqs.com/actor/Outsider) — 1

## Tracked threats

The 30 most recent of 58 tracked threats that use T1056.003.

- [Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…](https://intel.threadlinqs.com/threat/TL-2026-2919) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2627) — medium — 2026-09-23
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2626) — medium — 2026-09-23
- [Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…](https://intel.threadlinqs.com/threat/TL-2026-2567) — medium — 2026-09-18
- [Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details](https://intel.threadlinqs.com/threat/TL-2026-2562) — medium — 2026-09-18
- [Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow](https://intel.threadlinqs.com/threat/TL-2026-2556) — medium — 2026-09-18
- [Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data](https://intel.threadlinqs.com/threat/TL-2026-2550) — high — 2026-09-17
- [Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpit](https://intel.threadlinqs.com/threat/TL-2026-2490) — high — 2026-09-14
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2372) — high — 2026-09-07
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2273) — high — 2026-09-01
- [HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2](https://intel.threadlinqs.com/threat/TL-2026-2251) — high — 2026-08-31
- [Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit](https://intel.threadlinqs.com/threat/TL-2026-2246) — medium — 2026-08-30
- [AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypass](https://intel.threadlinqs.com/threat/TL-2026-2164) — high — 2026-08-27
- [Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…](https://intel.threadlinqs.com/threat/TL-2026-2143) — critical — 2026-08-25
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — high — 2026-08-18
- [Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)](https://intel.threadlinqs.com/threat/TL-2026-2024) — high — 2026-08-15
- [TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms](https://intel.threadlinqs.com/threat/TL-2026-2019) — medium — 2026-08-14
- [Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side](https://intel.threadlinqs.com/threat/TL-2026-2002) — high — 2026-08-13
- [Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East…](https://intel.threadlinqs.com/threat/TL-2026-1944) — high — 2026-08-08
- [Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…](https://intel.threadlinqs.com/threat/TL-2026-1816) — high — 2026-08-02
- [GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs](https://intel.threadlinqs.com/threat/TL-2026-1768) — high — 2026-07-30
- [Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brands](https://intel.threadlinqs.com/threat/TL-2026-1731) — medium — 2026-07-27
- [Operation RoundPress: TA458 Deploys SpyPress Malware via Half-Click Webmail Zero-Days (CVE-2025-27915…](https://intel.threadlinqs.com/threat/TL-2026-2579) — critical — 2026-07-23
- [Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…](https://intel.threadlinqs.com/threat/TL-2026-1643) — high — 2026-07-22
- [Google Ads MMC Sync Phishing Campaign Uses Fake Maintenance Notices for Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-2535) — medium — 2026-07-21

## Related CVEs

CVEs referenced by the tracked threats that use T1056.003, most frequent first.

- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2022-2586](https://intel.threadlinqs.com/cve/CVE-2022-2586)
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487)
- [CVE-2023-4911](https://intel.threadlinqs.com/cve/CVE-2023-4911)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-27915](https://intel.threadlinqs.com/cve/CVE-2025-27915)
- [CVE-2025-3929](https://intel.threadlinqs.com/cve/CVE-2025-3929)
- [CVE-2025-68461](https://intel.threadlinqs.com/cve/CVE-2025-68461)
- [CVE-2026-8496](https://intel.threadlinqs.com/cve/CVE-2026-8496)

## Detection coverage

Threadlinqs maintains 174 detection rules mapped to T1056.003 (SPL 57, KQL 54, Sigma 63). Rule content is available to Blue tier accounts and above; this page shows counts only.

174 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1056 Input Capture](https://intel.threadlinqs.com/technique/T1056) — 285 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1056.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
