# T1069.003 Cloud Groups

> As of 2026-10-05, T1069.003 (Cloud Groups) appears in 16 tracked threats, first reported 2026-05-19 and most recently 2026-09-13, with linked actors including Greatness PhaaS Operators, TheHatman, Kali365; it most often appears alongside T1078.004 (Cloud Accounts).

- **Tracked threats:** 16 (2 critical, 12 high, 2 medium)
- **First seen:** 2026-05-19
- **Last seen:** 2026-09-13
- **Threat actors:** 8
- **Detection rules:** 31 (counts only; Blue tier and above)

## Key facts

- **ID:** T1069.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Parent:** T1069
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1069/003/

## Activity timeline

T1069.003 first appeared in tracked threats on 2026-05-19 and was most recently reported on 2026-09-13. The busiest month was 2026-08 with 8 reports, and 16 of the 16 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1069.003 Cloud Groups is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of [T1069 Permission Groups Discovery](https://intel.threadlinqs.com/technique/T1069). Threadlinqs maps 16 of 2623 tracked threats (0.6%) to it; by severity that is 2 critical, 12 high, 2 medium.

Threats that use T1069.003 most often also use [T1078.004 Cloud Accounts](https://intel.threadlinqs.com/technique/T1078.004) (14 threats), [T1087.004 Cloud Account](https://intel.threadlinqs.com/technique/T1087.004) (14 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (10 threats), [T1530 Data from Cloud Storage](https://intel.threadlinqs.com/technique/T1530) (10 threats), [T1550.001 Application Access Token](https://intel.threadlinqs.com/technique/T1550.001) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1069.003; the most frequent are [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) (2), [TheHatman](https://intel.threadlinqs.com/actor/TheHatman) (2), [Kali365](https://intel.threadlinqs.com/actor/Kali365) (1), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (1), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (1).

## Data sources

Telemetry that can reveal T1069.003, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- Group — Group Enumeration, Group Metadata
- Process — Process Creation

## Threat actors using it

- [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) — 2
- [TheHatman](https://intel.threadlinqs.com/actor/TheHatman) — 2
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 1
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 1
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 1
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 1

## Tracked threats

16 tracked threats use T1069.003.

- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS](https://intel.threadlinqs.com/threat/TL-2026-2028) — high — 2026-08-16
- ["TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…](https://intel.threadlinqs.com/threat/TL-2026-2027) — high — 2026-08-16
- [OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio…](https://intel.threadlinqs.com/threat/TL-2026-2018) — high — 2026-08-14
- [Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)](https://intel.threadlinqs.com/threat/TL-2026-2009) — medium — 2026-08-13
- [AWS IAM Privilege Escalation Attack Path via iam:CreateAccessKey, iam:UpdateLoginProfile, and…](https://intel.threadlinqs.com/threat/TL-2026-2000) — medium — 2026-08-12
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens](https://intel.threadlinqs.com/threat/TL-2026-1873) — high — 2026-08-04
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1871) — high — 2026-08-04
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [GCP Cross-Project Compute Image Exfiltration via Compromised Developer Credentials](https://intel.threadlinqs.com/threat/TL-2026-1648) — high — 2026-07-23
- [Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths…](https://intel.threadlinqs.com/threat/TL-2026-1288) — high — 2026-07-14
- [BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1060) — high — 2026-07-02
- [ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1037) — high — 2026-07-01
- [Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0560) — high — 2026-05-22
- [Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0529) — critical — 2026-05-19

## Related CVEs

CVEs referenced by the tracked threats that use T1069.003, most frequent first.

- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2025-62554](https://intel.threadlinqs.com/cve/CVE-2025-62554)
- [CVE-2025-62557](https://intel.threadlinqs.com/cve/CVE-2025-62557)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)
- [CVE-2026-66014](https://intel.threadlinqs.com/cve/CVE-2026-66014)

## Detection coverage

Threadlinqs maintains 31 detection rules mapped to T1069.003 (SPL 9, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

31 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1069 Permission Groups Discovery](https://intel.threadlinqs.com/technique/T1069) — 101 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1069.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
