# T1056.004 Credential API Hooking

> As of 2026-10-05, T1056.004 (Credential API Hooking) appears in 14 tracked threats, first reported 2026-03-02 and most recently 2026-09-21, with linked actors including APT29, Handala Hack, Midnight Blizzard; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 14 (3 critical, 9 high, 2 medium)
- **First seen:** 2026-03-02
- **Last seen:** 2026-09-21
- **Threat actors:** 9
- **Detection rules:** 26 (counts only; Blue tier and above)

## Key facts

- **ID:** T1056.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access, Collection
- **Matrix:** Enterprise
- **Parent:** T1056
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1056/004/

## Activity timeline

T1056.004 first appeared in tracked threats on 2026-03-02 and was most recently reported on 2026-09-21. The busiest month was 2026-07 with 5 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1056.004 Credential API Hooking is catalogued by MITRE ATT&CK under the Credential Access and Collection tactics in the Enterprise matrix, as a sub-technique of [T1056 Input Capture](https://intel.threadlinqs.com/technique/T1056). Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 3 critical, 9 high, 2 medium.

Threats that use T1056.004 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (13 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (11 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (9 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1056.004; the most frequent are [APT29](https://intel.threadlinqs.com/actor/APT29) (1), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (1), [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) (1), [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) (1), [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) (1).

## Data sources

Telemetry that can reveal T1056.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Module — Module Load
- Process — OS API Execution, Process Metadata

## Threat actors using it

- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 1
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 1
- [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) — 1
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1
- [UNC2452](https://intel.threadlinqs.com/actor/UNC2452) — 1
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 1
- [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat) — 1

## Tracked threats

14 tracked threats use T1056.004.

- [EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials](https://intel.threadlinqs.com/threat/TL-2026-2600) — critical — 2026-09-21
- [Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…](https://intel.threadlinqs.com/threat/TL-2026-2446) — high — 2026-09-11
- [TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate Transparency](https://intel.threadlinqs.com/threat/TL-2026-2133) — high — 2026-08-24
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loader](https://intel.threadlinqs.com/threat/TL-2026-1387) — critical — 2026-07-15
- [June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…](https://intel.threadlinqs.com/threat/TL-2026-1353) — medium — 2026-07-15
- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…](https://intel.threadlinqs.com/threat/TL-2026-1309) — medium — 2026-07-14
- [Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading…](https://intel.threadlinqs.com/threat/TL-2026-1038) — high — 2026-07-01
- [StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption)](https://intel.threadlinqs.com/threat/TL-2026-0941) — high — 2026-06-25
- [Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…](https://intel.threadlinqs.com/threat/TL-2026-0583) — high — 2026-05-25
- [FEMITBOT — Telegram Mini Apps Abused for Crypto Scams, Brand Impersonation & Android APK Malware Delivery…](https://intel.threadlinqs.com/threat/TL-2026-0450) — high — 2026-05-03
- [Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCP](https://intel.threadlinqs.com/threat/TL-2026-0429) — critical — 2026-04-27
- [Remcos RAT Phishing Campaign Abusing Google Cloud Storage (storage.googleapis.com) with RegSvcs.exe Process…](https://intel.threadlinqs.com/threat/TL-2026-0409) — high — 2026-04-22
- [Malicious Go crypto Module — Rekoobe Linux Backdoor via golang.org/x/crypto Namespace Confusion](https://intel.threadlinqs.com/threat/TL-2026-0164) — high — 2026-03-02

## Related CVEs

CVEs referenced by the tracked threats that use T1056.004, most frequent first.

- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)

## Detection coverage

Threadlinqs maintains 26 detection rules mapped to T1056.004 (SPL 5, KQL 12, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.

26 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1056 Input Capture](https://intel.threadlinqs.com/technique/T1056) — 285 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1056.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
