# T1098.001 Additional Cloud Credentials

> As of 2026-10-05, T1098.001 (Additional Cloud Credentials) appears in 32 tracked threats, first reported 2026-02-02 and most recently 2026-09-01, with linked actors including ShinyHunters, Bling Libra, Scattered LAPSUS$ Hunters; it most often appears alongside T1528 (Steal Application Access Token).

- **Tracked threats:** 32 (11 critical, 17 high, 3 medium, 1 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-01
- **Threat actors:** 26
- **Detection rules:** 85 (counts only; Blue tier and above)

## Key facts

- **ID:** T1098.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1098
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1098/001/

## Activity timeline

T1098.001 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-01. The busiest month was 2026-07 with 7 reports, and 32 of the 32 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1098.001 Additional Cloud Credentials is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098). Threadlinqs maps 32 of 2623 tracked threats (1.2%) to it; by severity that is 11 critical, 17 high, 3 medium, 1 low.

Threats that use T1098.001 most often also use [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (21 threats), [T1078.004 Cloud Accounts](https://intel.threadlinqs.com/technique/T1078.004) (20 threats), [T1526 Cloud Service Discovery](https://intel.threadlinqs.com/technique/T1526) (16 threats), [T1550.001 Application Access Token](https://intel.threadlinqs.com/technique/T1550.001) (16 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

26 tracked threat actors appear in the threats that use T1098.001; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (4), [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) (3), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (3), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (3), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (3).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1098.001.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1098.001, per MITRE ATT&CK.

- Active Directory — Active Directory Object Creation, Active Directory Object Modification
- User Account — User Account Modification

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 3
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 3
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 3
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 3
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 3
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 3
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 3
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 3
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1

## Tracked threats

The 30 most recent of 32 tracked threats that use T1098.001.

- [FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial…](https://intel.threadlinqs.com/threat/TL-2026-2286) — high — 2026-09-01
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…](https://intel.threadlinqs.com/threat/TL-2026-2107) — critical — 2026-08-22
- [AWS IAM Privilege Escalation Attack Path via iam:CreateAccessKey, iam:UpdateLoginProfile, and…](https://intel.threadlinqs.com/threat/TL-2026-2000) — medium — 2026-08-12
- [Metabase Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited in the Wild for Unauthenticated Admin Access](https://intel.threadlinqs.com/threat/TL-2026-1940) — critical — 2026-08-08
- [Unauthenticated Metabase SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework and Tally…](https://intel.threadlinqs.com/threat/TL-2026-1937) — critical — 2026-08-07
- [Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud](https://intel.threadlinqs.com/threat/TL-2026-1826) — low — 2026-08-03
- [OAuth Consent Phishing Abuses Microsoft's Legitimate Login System to Harvest Microsoft 365 Tokens](https://intel.threadlinqs.com/threat/TL-2026-1778) — high — 2026-07-30
- [Abuse of AWS Systems Manager (SSM) Agent as a Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1644) — medium — 2026-07-22
- ["The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…](https://intel.threadlinqs.com/threat/TL-2026-1593) — high — 2026-07-21
- [HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy…](https://intel.threadlinqs.com/threat/TL-2026-1561) — high — 2026-07-20
- [npm 12 Disables Install Scripts, Git Dependencies, and Remote Tarball URLs by Default to Curb Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-1163) — medium — 2026-07-10
- [ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1037) — high — 2026-07-01
- [ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1036) — high — 2026-07-01
- [Cordyceps: Systemic CI/CD Workflow Flaws Expose 300+ GitHub Repositories (Microsoft, Google, Apache…](https://intel.threadlinqs.com/threat/TL-2026-1021) — critical — 2026-06-30
- [Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign](https://intel.threadlinqs.com/threat/TL-2026-0984) — critical — 2026-06-28
- [Amazon Q Developer Extension Trust-Boundary & Symlink Flaws (CVE-2026-12957, CVE-2026-12958) Auto-Execute…](https://intel.threadlinqs.com/threat/TL-2026-0950) — high — 2026-06-26
- [Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines…](https://intel.threadlinqs.com/threat/TL-2026-0928) — critical — 2026-06-23
- [EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…](https://intel.threadlinqs.com/threat/TL-2026-0888) — high — 2026-06-20
- [Four Methods for Azure Blob Storage Ransomware: Client-Side Bulk Encryption, CPK, Encryption Scope, and CMK…](https://intel.threadlinqs.com/threat/TL-2026-2191) — high — 2026-06-15
- [VaultJacking — Google Password Manager Vault Theft via Single Captured 6-Digit PIN (PhishU Framework)](https://intel.threadlinqs.com/threat/TL-2026-0620) — high — 2026-05-28
- [Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…](https://intel.threadlinqs.com/threat/TL-2026-0548) — critical — 2026-05-21
- [Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0529) — critical — 2026-05-19
- [BerriAI LiteLLM Unauthenticated SQL Injection in Proxy API Key Verification (CVE-2026-42208) — CVSS 9.8…](https://intel.threadlinqs.com/threat/TL-2026-0506) — critical — 2026-05-13
- [Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM Access Keys (Securelist, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0451) — high — 2026-05-04
- [Mini Shai-Hulud Resurfaces — intercom-client@7.0.4 npm Worm Harvesting GitHub & Cloud Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-0446) — critical — 2026-04-30
- [Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2…](https://intel.threadlinqs.com/threat/TL-2026-0424) — high — 2026-04-25
- [Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and…](https://intel.threadlinqs.com/threat/TL-2026-0394) — high — 2026-04-20
- [Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation…](https://intel.threadlinqs.com/threat/TL-2026-0266) — critical — 2026-03-21
- [State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database…](https://intel.threadlinqs.com/threat/TL-2026-0111) — high — 2026-02-16
- [ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-0054) — high — 2026-02-03

## Related CVEs

CVEs referenced by the tracked threats that use T1098.001, most frequent first.

- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-12957](https://intel.threadlinqs.com/cve/CVE-2026-12957)
- [CVE-2026-12958](https://intel.threadlinqs.com/cve/CVE-2026-12958)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-42208](https://intel.threadlinqs.com/cve/CVE-2026-42208)
- [CVE-2026-69836](https://intel.threadlinqs.com/cve/CVE-2026-69836)

## Detection coverage

Threadlinqs maintains 85 detection rules mapped to T1098.001 (SPL 27, KQL 32, Sigma 26). Rule content is available to Blue tier accounts and above; this page shows counts only.

85 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098) — 288 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1098.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
