# T1213.003 Code Repositories

> As of 2026-10-05, T1213.003 (Code Repositories) appears in 26 tracked threats, first reported 2026-02-03 and most recently 2026-09-29, with linked actors including Hacktron AI, ShinyHunters, TeamPCP; it most often appears alongside T1552.001 (Credentials In Files).

- **Tracked threats:** 26 (11 critical, 13 high, 1 medium)
- **First seen:** 2026-02-03
- **Last seen:** 2026-09-29
- **Threat actors:** 9
- **Detection rules:** 53 (counts only; Blue tier and above)

## Key facts

- **ID:** T1213.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Parent:** T1213
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1213/003/

## Activity timeline

T1213.003 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-09-29. The busiest month was 2026-09 with 7 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1213.003 Code Repositories is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix, as a sub-technique of [T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213). Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 11 critical, 13 high, 1 medium.

Threats that use T1213.003 most often also use [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (15 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (14 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (13 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (11 threats), [T1199 Trusted Relationship](https://intel.threadlinqs.com/technique/T1199) (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1213.003; the most frequent are [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) (2), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (2), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (2), [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) (1), [Coinbase Cartel](https://intel.threadlinqs.com/actor/Coinbase%20Cartel) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1213.003.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1213.003, per MITRE ATT&CK.

- Application Log — Application Log Content
- Logon Session — Logon Session Creation

## Threat actors using it

- [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) — 2
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 2
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 1
- [Coinbase Cartel](https://intel.threadlinqs.com/actor/Coinbase%20Cartel) — 1
- [CoinbaseCartel](https://intel.threadlinqs.com/actor/CoinbaseCartel) — 1
- [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) — 1
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 1
- [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) — 1

## Tracked threats

26 tracked threats use T1213.003.

- [Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials…](https://intel.threadlinqs.com/threat/TL-2026-2772) — critical — 2026-09-29
- [Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…](https://intel.threadlinqs.com/threat/TL-2026-2661) — high — 2026-09-26
- [AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access](https://intel.threadlinqs.com/threat/TL-2026-2568) — high — 2026-09-18
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…](https://intel.threadlinqs.com/threat/TL-2026-2442) — critical — 2026-09-11
- [Frontier AI Agents Compress Full Enterprise Intrusion Chain into Under 10 Hours (Unit 42 Investigation)](https://intel.threadlinqs.com/threat/TL-2026-2341) — high — 2026-09-05
- [Coordinated GitHub API Enumeration and Access Token Abuse Campaign](https://intel.threadlinqs.com/threat/TL-2026-2339) — high — 2026-09-05
- [Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…](https://intel.threadlinqs.com/threat/TL-2026-2048) — critical — 2026-08-17
- [Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)](https://intel.threadlinqs.com/threat/TL-2026-2009) — medium — 2026-08-13
- [RovoBlast: One-Click rovoChatPrompt Parameter-to-Prompt Injection in Atlassian Rovo Exposes Confluence…](https://intel.threadlinqs.com/threat/TL-2026-1939) — critical — 2026-08-08
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1871) — high — 2026-08-04
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [GitLab RCE Chain via Malicious Jupyter Notebooks Exploiting Oj Ruby JSON Parser Flaws](https://intel.threadlinqs.com/threat/TL-2026-1715) — critical — 2026-07-27
- [Capital One Open-Sources VulnHunter: Agentic, Claude-Opus-4.8-Powered Vulnerability Detection and…](https://intel.threadlinqs.com/threat/TL-2026-1583) — 2026-07-21
- [Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and…](https://intel.threadlinqs.com/threat/TL-2026-1318) — critical — 2026-07-14
- [Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines…](https://intel.threadlinqs.com/threat/TL-2026-0928) — critical — 2026-06-23
- [Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container…](https://intel.threadlinqs.com/threat/TL-2026-0602) — high — 2026-05-27
- [Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…](https://intel.threadlinqs.com/threat/TL-2026-0547) — critical — 2026-05-21
- [Grafana Labs Source Code Theft via Stolen GitHub Access Token — CoinbaseCartel Extortion Campaign](https://intel.threadlinqs.com/threat/TL-2026-0527) — high — 2026-05-18
- [Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM Access Keys (Securelist, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0451) — high — 2026-05-04
- [GitHub.com & GitHub Enterprise Server Pre-Auth RCE via X-Stat Header Field Injection (CVE-2026-3854)](https://intel.threadlinqs.com/threat/TL-2026-0434) — high — 2026-04-29
- [Vercel April 2026 Security Incident — Context.ai OAuth Compromise Leads to Google Workspace Takeover and…](https://intel.threadlinqs.com/threat/TL-2026-0394) — high — 2026-04-20
- [Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…](https://intel.threadlinqs.com/threat/TL-2026-0123) — critical — 2026-02-21
- [CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS…](https://intel.threadlinqs.com/threat/TL-2026-0110) — critical — 2026-02-16
- [GitHub Codespaces RCE via VS Code Configuration Files](https://intel.threadlinqs.com/threat/TL-2026-0100) — high — 2026-02-16
- [GitLab CI Lint API SSRF — CVE-2021-39935 Patch Bypass, CISA KEV Feb 2026, Cloud Metadata Theft, Internal…](https://intel.threadlinqs.com/threat/TL-2026-0089) — high — 2026-02-03

## Related CVEs

CVEs referenced by the tracked threats that use T1213.003, most frequent first.

- [CVE-2021-39935](https://intel.threadlinqs.com/cve/CVE-2021-39935)
- [CVE-2024-12356](https://intel.threadlinqs.com/cve/CVE-2024-12356)
- [CVE-2024-12686](https://intel.threadlinqs.com/cve/CVE-2024-12686)
- [CVE-2025-1094](https://intel.threadlinqs.com/cve/CVE-2025-1094)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-19478](https://intel.threadlinqs.com/cve/CVE-2026-19478)
- [CVE-2026-19650](https://intel.threadlinqs.com/cve/CVE-2026-19650)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-27771](https://intel.threadlinqs.com/cve/CVE-2026-27771)
- [CVE-2026-3854](https://intel.threadlinqs.com/cve/CVE-2026-3854)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)
- [CVE-2026-85706](https://intel.threadlinqs.com/cve/CVE-2026-85706)
- [CVE-2026-87719](https://intel.threadlinqs.com/cve/CVE-2026-87719)

## Detection coverage

Threadlinqs maintains 53 detection rules mapped to T1213.003 (SPL 18, KQL 20, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.

53 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213) — 412 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1213.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
