Activity timeline
T1213.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 7 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1213.003 Code Repositories is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix, as a sub-technique of T1213 Data from Information Repositories. Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 11 critical, 13 high, 1 medium.
Threats that use T1213.003 most often also use T1552.001 Credentials In Files (15 threats), T1528 Steal Application Access Token (14 threats), T1190 Exploit Public-Facing Application (13 threats), T1078 Valid Accounts (11 threats), T1199 Trusted Relationship (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1213.003; the most frequent are Hacktron AI (2), ShinyHunters (2), TeamPCP (2), Bling Libra (1), Coinbase Cartel (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1213.003.
Data sources
Telemetry that can reveal T1213.003, per MITRE ATT&CK.
- Application Log — Application Log Content
- Logon Session — Logon Session Creation
Threat actors using it
Tracked threats
26 tracked threats use T1213.003.
- Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials…critical
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…high
- AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Accesshigh
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- Frontier AI Agents Compress Full Enterprise Intrusion Chain into Under 10 Hours (Unit 42 Investigation)high
- Coordinated GitHub API Enumeration and Access Token Abuse Campaignhigh
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…critical
- Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)medium
- RovoBlast: One-Click rovoChatPrompt Parameter-to-Prompt Injection in Atlassian Rovo Exposes Confluence…critical
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…high
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- GitLab RCE Chain via Malicious Jupyter Notebooks Exploiting Oj Ruby JSON Parser Flawscritical
- Capital One Open-Sources VulnHunter: Agentic, Claude-Opus-4.8-Powered Vulnerability Detection and…
- Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and…critical
- Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines…critical
- Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container…high
- Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…critical
- Grafana Labs Source Code Theft via Stolen GitHub Access Token — CoinbaseCartel Extortion Campaignhigh
- Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM Access Keys (Securelist, May 2026)high
- GitHub.com & GitHub Enterprise Server Pre-Auth RCE via X-Stat Header Field Injection (CVE-2026-3854)high
- Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and…high
- Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…critical
- CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS…critical
- GitHub Codespaces RCE via VS Code Configuration Fileshigh
- GitLab CI Lint API SSRF — CVE-2021-39935 Patch Bypass, CISA KEV Feb 2026, Cloud Metadata Theft, Internal…high
Detection coverage
Threadlinqs maintains 53 detection rules mapped to T1213.003 (SPL 18, KQL 20, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1213 Data from Information Repositories — 412 tracked threats at the technique level.