Activity timeline
T1213.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 20 of the 20 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1213.002 Sharepoint is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix, as a sub-technique of T1213 Data from Information Repositories. Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 6 critical, 14 high.
Threats that use T1213.002 most often also use T1530 Data from Cloud Storage (10 threats), T1657 Financial Theft (10 threats), T1071.001 Web Protocols (9 threats), T1078.004 Cloud Accounts (9 threats), T1528 Steal Application Access Token (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
15 tracked threat actors appear in the threats that use T1213.002; the most frequent are FSB Center 16 (2), Sandworm (2), Static Tundra (2), Greatness PhaaS Operators (1), Kali365 (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1213.002.
Data sources
Telemetry that can reveal T1213.002, per MITRE ATT&CK.
- Application Log — Application Log Content
- Cloud Service — Cloud Service Metadata
- Logon Session — Logon Session Creation
Threat actors using it
Tracked threats
20 tracked threats use T1213.002.
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…high
- RovoBlast: One-Click Parameter-to-Prompt Injection in Atlassian Rovo AI Exposes Confluence, Jira, and…critical
- RovoBlast: One-Click rovoChatPrompt Parameter-to-Prompt Injection in Atlassian Rovo Exposes Confluence…critical
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijackinghigh
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…high
- OAuth Consent Phishing Abuses Microsoft's Legitimate Login System to Harvest Microsoft 365 Tokenshigh
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattackhigh
- Actively Exploited SharePoint Server Elevation of Privilege Flaw (CVE-2026-56164) Patched Alongside Critical…critical
- O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack…high
- ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens…high
- EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…high
- UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting…high
- Microsoft SharePoint Authenticated RCE via Deserialization of Untrusted Data (CVE-2026-45659)high
- Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass…high
- Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltrationcritical
- Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon…high
- Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWipercritical
- Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructurecritical
Detection coverage
Threadlinqs maintains 39 detection rules mapped to T1213.002 (SPL 16, KQL 13, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1213 Data from Information Repositories — 412 tracked threats at the technique level.