Threadlinqs IntelligenceStart free

ATT&CK techniqueCredential Access

T1111 Multi-Factor Authentication Interception

Credential AccessEnterprise

As of 2026-10-05, T1111 (Multi-Factor Authentication Interception) appears in 121 tracked threats, first reported 2026-02-02 and most recently 2026-10-04, with linked actors including UNC6671, APT28, ShinyHunters; it most often appears alongside T1539 (Steal Web Session Cookie).

Tracked threats
12124 critical, 83 high, 14 medium
First seen
2026-02-02
Last seen
2026-10-04
Threat actors
43In the threats using it
Detection rules
181Blue tier and above

Data as of:

Activity timeline

T1111 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 56 reports, and 121 of the 121 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1111 Multi-Factor Authentication Interception is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 121 of 2623 tracked threats (4.6%) to it; by severity that is 24 critical, 83 high, 14 medium.

Threats that use T1111 most often also use T1539 Steal Web Session Cookie (62 threats), T1684.001 Impersonation (55 threats), T1657 Financial Theft (52 threats), T1566 Phishing (51 threats), T1027 Obfuscated Files or Information (49 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

43 tracked threat actors appear in the threats that use T1111; the most frequent are UNC6671 (4), APT28 (3), ShinyHunters (3), UNC6240 (3), UNC6395 (3).

Mitigations

MITRE ATT&CK lists 1 mitigation for T1111.

Data sources

Telemetry that can reveal T1111, per MITRE ATT&CK.

  • Driver — Driver Load
  • Process — OS API Execution
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 121 tracked threats that use T1111.

Detection coverage

Threadlinqs maintains 181 detection rules mapped to T1111 (SPL 58, KQL 73, Sigma 50). Rule content is available to Blue tier accounts and above; this page shows counts only.

181 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans