Activity timeline
T1056.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1056.004 Credential API Hooking is catalogued by MITRE ATT&CK under the Credential Access and Collection tactics in the Enterprise matrix, as a sub-technique of T1056 Input Capture. Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 3 critical, 9 high, 2 medium.
Threats that use T1056.004 most often also use T1071.001 Web Protocols (13 threats), T1041 Exfiltration Over C2 Channel (11 threats), T1027 Obfuscated Files or Information (10 threats), T1140 Deobfuscate/Decode Files or Information (9 threats), T1204.002 Malicious File (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1056.004; the most frequent are APT29 (1), Handala Hack (1), Midnight Blizzard (1), Periwinkle Tempest (1), Shai-Hulud (1).
Data sources
Telemetry that can reveal T1056.004, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Modification
- Module — Module Load
- Process — OS API Execution, Process Metadata
Threat actors using it
Tracked threats
14 tracked threats use T1056.004.
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentialscritical
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…high
- TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate Transparencyhigh
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loadercritical
- June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…medium
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…medium
- Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading…high
- StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption)high
- Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…high
- FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand Impersonation & Android APK Malware Delivery…high
- Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCPcritical
- Remcos RAT Phishing Campaign Abusing Google Cloud Storage (storage.googleapis.com) with RegSvcs.exe Process…high
- Malicious Go crypto Module — Rekoobe Linux Backdoor via golang.org/x/crypto Namespace Confusionhigh
Detection coverage
Threadlinqs maintains 26 detection rules mapped to T1056.004 (SPL 5, KQL 12, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1056 Input Capture — 285 tracked threats at the technique level.