# T1111 Multi-Factor Authentication Interception

> As of 2026-10-05, T1111 (Multi-Factor Authentication Interception) appears in 121 tracked threats, first reported 2026-02-02 and most recently 2026-10-04, with linked actors including UNC6671, APT28, ShinyHunters; it most often appears alongside T1539 (Steal Web Session Cookie).

- **Tracked threats:** 121 (24 critical, 83 high, 14 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-04
- **Threat actors:** 43
- **Detection rules:** 181 (counts only; Blue tier and above)

## Key facts

- **ID:** T1111
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1111/

## Activity timeline

T1111 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 56 reports, and 121 of the 121 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1111 Multi-Factor Authentication Interception is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 121 of 2623 tracked threats (4.6%) to it; by severity that is 24 critical, 83 high, 14 medium.

Threats that use T1111 most often also use [T1539 Steal Web Session Cookie](https://intel.threadlinqs.com/technique/T1539) (62 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (55 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (52 threats), [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (51 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (49 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

43 tracked threat actors appear in the threats that use T1111; the most frequent are [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) (4), [APT28](https://intel.threadlinqs.com/actor/APT28) (3), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (3), [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) (3), [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) (3).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1111.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)

## Data sources

Telemetry that can reveal T1111, per MITRE ATT&CK.

- Driver — Driver Load
- Process — OS API Execution
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 4
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 3
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 3
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 3
- [Balonx](https://intel.threadlinqs.com/actor/Balonx) — 2
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 2
- [DarkSpectre](https://intel.threadlinqs.com/actor/DarkSpectre) — 2
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 2
- [Forg365 operators](https://intel.threadlinqs.com/actor/Forg365%20operators) — 2
- [Milk Dragon](https://intel.threadlinqs.com/actor/Milk%20Dragon) — 2
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 2

## Tracked threats

The 30 most recent of 121 tracked threats that use T1111.

- [Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…](https://intel.threadlinqs.com/threat/TL-2026-2919) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA](https://intel.threadlinqs.com/threat/TL-2026-2834) — high — 2026-10-01
- [Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…](https://intel.threadlinqs.com/threat/TL-2026-2770) — medium — 2026-09-29
- [Fake American Express "non-compliance" card-lock phishing campaign targets Australians](https://intel.threadlinqs.com/threat/TL-2026-2758) — medium — 2026-09-29
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — medium — 2026-09-25
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow](https://intel.threadlinqs.com/threat/TL-2026-2556) — medium — 2026-09-18
- [Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…](https://intel.threadlinqs.com/threat/TL-2026-2548) — medium — 2026-09-17
- [Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)](https://intel.threadlinqs.com/threat/TL-2026-2529) — high — 2026-09-15
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…](https://intel.threadlinqs.com/threat/TL-2026-2315) — high — 2026-09-03
- [SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-2307) — critical — 2026-09-03
- [Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts](https://intel.threadlinqs.com/threat/TL-2026-2167) — high — 2026-08-27
- [AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypass](https://intel.threadlinqs.com/threat/TL-2026-2164) — high — 2026-08-27
- [Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…](https://intel.threadlinqs.com/threat/TL-2026-2170) — high — 2026-08-26
- [Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…](https://intel.threadlinqs.com/threat/TL-2026-2143) — critical — 2026-08-25
- [Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login Flows](https://intel.threadlinqs.com/threat/TL-2026-2140) — high — 2026-08-25
- [Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-2072) — high — 2026-08-19
- [Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains](https://intel.threadlinqs.com/threat/TL-2026-2050) — high — 2026-08-17
- [Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)](https://intel.threadlinqs.com/threat/TL-2026-2024) — high — 2026-08-15
- [UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data…](https://intel.threadlinqs.com/threat/TL-2026-1962) — high — 2026-08-09
- [UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…](https://intel.threadlinqs.com/threat/TL-2026-1959) — critical — 2026-08-09
- [Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts](https://intel.threadlinqs.com/threat/TL-2026-1953) — high — 2026-08-09
- [Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra ID](https://intel.threadlinqs.com/threat/TL-2026-1952) — high — 2026-08-09
- [Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1923) — high — 2026-08-07
- [Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication](https://intel.threadlinqs.com/threat/TL-2026-1842) — critical — 2026-08-03
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31

## Related CVEs

CVEs referenced by the tracked threats that use T1111, most frequent first.

- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2024-11182](https://intel.threadlinqs.com/cve/CVE-2024-11182)
- [CVE-2024-27443](https://intel.threadlinqs.com/cve/CVE-2024-27443)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-27915](https://intel.threadlinqs.com/cve/CVE-2025-27915)
- [CVE-2025-3929](https://intel.threadlinqs.com/cve/CVE-2025-3929)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-10735](https://intel.threadlinqs.com/cve/CVE-2026-10735)
- [CVE-2026-26083](https://intel.threadlinqs.com/cve/CVE-2026-26083)
- [CVE-2026-34348](https://intel.threadlinqs.com/cve/CVE-2026-34348)
- [CVE-2026-42824](https://intel.threadlinqs.com/cve/CVE-2026-42824)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2026-44277](https://intel.threadlinqs.com/cve/CVE-2026-44277)
- [CVE-2026-48558](https://intel.threadlinqs.com/cve/CVE-2026-48558)
- [CVE-2026-49777](https://intel.threadlinqs.com/cve/CVE-2026-49777)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)

## Detection coverage

Threadlinqs maintains 181 detection rules mapped to T1111 (SPL 58, KQL 73, Sigma 50). Rule content is available to Blue tier accounts and above; this page shows counts only.

181 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1111
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
