# T1212 Exploitation for Credential Access

> As of 2026-10-05, T1212 (Exploitation for Credential Access) appears in 92 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including INC Ransom, INC Ransom - G1032, JADEPUFFER; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 92 (63 critical, 25 high, 4 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 9
- **Detection rules:** 96 (counts only; Blue tier and above)

## Key facts

- **ID:** T1212
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1212/

## Activity timeline

T1212 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 30 reports, and 92 of the 92 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1212 Exploitation for Credential Access is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 92 of 2623 tracked threats (3.5%) to it; by severity that is 63 critical, 25 high, 4 medium.

Threats that use T1212 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (77 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (55 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (49 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (48 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (48 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1212; the most frequent are [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) (2), [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) (2), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) (2), [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) (1), [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) (1).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1212.

- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)
- [M1019 Threat Intelligence Program](https://attack.mitre.org/mitigations/M1019/)
- [M1048 Application Isolation and Sandboxing](https://attack.mitre.org/mitigations/M1048/)
- [M1050 Exploit Protection](https://attack.mitre.org/mitigations/M1050/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1212, per MITRE ATT&CK.

- Application Log — Application Log Content
- Process — Process Creation
- User Account — User Account Authentication

## Threat actors using it

- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 2
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 2
- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 2
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 1
- [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) — 1
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 1
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1
- [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1

## Tracked threats

The 30 most recent of 92 tracked threats that use T1212.

- [Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft…](https://intel.threadlinqs.com/threat/TL-2026-2874) — critical — 2026-10-03
- [Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and…](https://intel.threadlinqs.com/threat/TL-2026-2892) — high — 2026-10-02
- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…](https://intel.threadlinqs.com/threat/TL-2026-2851) — critical — 2026-10-02
- [Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS…](https://intel.threadlinqs.com/threat/TL-2026-2849) — high — 2026-09-29
- [Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses…](https://intel.threadlinqs.com/threat/TL-2026-2796) — high — 2026-09-29
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)](https://intel.threadlinqs.com/threat/TL-2026-2682) — high — 2026-09-27
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-2680) — critical — 2026-09-25
- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…](https://intel.threadlinqs.com/threat/TL-2026-2658) — medium — 2026-09-25
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…](https://intel.threadlinqs.com/threat/TL-2026-2458) — high — 2026-09-12
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV…](https://intel.threadlinqs.com/threat/TL-2026-2210) — critical — 2026-08-29
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth…](https://intel.threadlinqs.com/threat/TL-2026-2159) — critical — 2026-08-26
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…](https://intel.threadlinqs.com/threat/TL-2026-2152) — critical — 2026-08-26
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…](https://intel.threadlinqs.com/threat/TL-2026-2107) — critical — 2026-08-22
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [Metabase Zero-Day (GHSA-vwf4-m7j8-wcjf): Unauthenticated SQL Injection via /api/session/reset_password…](https://intel.threadlinqs.com/threat/TL-2026-1969) — critical — 2026-08-10
- ["When Agentic Glue Melts": Five workerd Memory-Corruption Flaws Enable Cross-Tenant Secret Theft and Code…](https://intel.threadlinqs.com/threat/TL-2026-1924) — critical — 2026-08-06
- [Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication](https://intel.threadlinqs.com/threat/TL-2026-1842) — critical — 2026-08-03
- [Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses](https://intel.threadlinqs.com/threat/TL-2026-1829) — critical — 2026-08-03
- [Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…](https://intel.threadlinqs.com/threat/TL-2026-1790) — critical — 2026-07-31
- [Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…](https://intel.threadlinqs.com/threat/TL-2026-1764) — critical — 2026-07-29
- [CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-1755) — critical — 2026-07-29
- [CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation](https://intel.threadlinqs.com/threat/TL-2026-1675) — critical — 2026-07-24
- [Apache Syncope Patches 12 CVEs Including Groovy Sandbox Bypass RCE and Audit Search SQLi](https://intel.threadlinqs.com/threat/TL-2026-1666) — critical — 2026-07-24
- [CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1650) — critical — 2026-07-23
- [Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026)](https://intel.threadlinqs.com/threat/TL-2026-1616) — high — 2026-07-22
- [CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password…](https://intel.threadlinqs.com/threat/TL-2026-1568) — high — 2026-07-20

## Related CVEs

CVEs referenced by the tracked threats that use T1212, most frequent first.

- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-53409](https://intel.threadlinqs.com/cve/CVE-2026-53409)
- [CVE-2026-53410](https://intel.threadlinqs.com/cve/CVE-2026-53410)
- [CVE-2026-53411](https://intel.threadlinqs.com/cve/CVE-2026-53411)
- [CVE-2026-53412](https://intel.threadlinqs.com/cve/CVE-2026-53412)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-42208](https://intel.threadlinqs.com/cve/CVE-2026-42208)
- [CVE-2026-4368](https://intel.threadlinqs.com/cve/CVE-2026-4368)
- [CVE-2026-48317](https://intel.threadlinqs.com/cve/CVE-2026-48317)
- [CVE-2026-48323](https://intel.threadlinqs.com/cve/CVE-2026-48323)
- [CVE-2026-48326](https://intel.threadlinqs.com/cve/CVE-2026-48326)
- [CVE-2026-48330](https://intel.threadlinqs.com/cve/CVE-2026-48330)
- [CVE-2026-48331](https://intel.threadlinqs.com/cve/CVE-2026-48331)
- [CVE-2026-48333](https://intel.threadlinqs.com/cve/CVE-2026-48333)
- [CVE-2026-48448](https://intel.threadlinqs.com/cve/CVE-2026-48448)
- [CVE-2026-48449](https://intel.threadlinqs.com/cve/CVE-2026-48449)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-67279](https://intel.threadlinqs.com/cve/CVE-2026-67279)
- [CVE-2026-8451](https://intel.threadlinqs.com/cve/CVE-2026-8451)
- [CVE-2012-1854](https://intel.threadlinqs.com/cve/CVE-2012-1854)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)

## Detection coverage

Threadlinqs maintains 96 detection rules mapped to T1212 (SPL 38, KQL 27, Sigma 30, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

96 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1212
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
