# T1526 Cloud Service Discovery

> As of 2026-10-05, T1526 (Cloud Service Discovery) appears in 157 tracked threats, first reported 2026-02-02 and most recently 2026-09-26, with linked actors including TeamPCP, ShinyHunters, Scattered LAPSUS$ Hunters; it most often appears alongside T1528 (Steal Application Access Token).

- **Tracked threats:** 157 (58 critical, 83 high, 15 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-26
- **Threat actors:** 46
- **Detection rules:** 124 (counts only; Blue tier and above)

## Key facts

- **ID:** T1526
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1526/

## Activity timeline

T1526 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-26. The busiest month was 2026-07 with 57 reports, and 157 of the 157 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1526 Cloud Service Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 157 of 2623 tracked threats (6%) to it; by severity that is 58 critical, 83 high, 15 medium.

Threats that use T1526 most often also use [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (104 threats), [T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213) (83 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (82 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (80 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (73 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

46 tracked threat actors appear in the threats that use T1526; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (12), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (10), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (5), [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) (5), [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) (4).

## Data sources

Telemetry that can reveal T1526, per MITRE ATT&CK.

- Cloud Service — Cloud Service Enumeration
- Logon Session — Logon Session Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 12
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 10
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 5
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 5
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 4
- [Icarus](https://intel.threadlinqs.com/actor/Icarus) — 4
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 4
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 4
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 4
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 4
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 3

## Tracked threats

The 30 most recent of 157 tracked threats that use T1526.

- [Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rows](https://intel.threadlinqs.com/threat/TL-2026-2675) — high — 2026-09-26
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize…](https://intel.threadlinqs.com/threat/TL-2026-2629) — critical — 2026-09-23
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain](https://intel.threadlinqs.com/threat/TL-2026-2601) — high — 2026-09-21
- [AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access](https://intel.threadlinqs.com/threat/TL-2026-2568) — high — 2026-09-18
- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Coordinated GitHub API Enumeration and Access Token Abuse Campaign](https://intel.threadlinqs.com/threat/TL-2026-2339) — high — 2026-09-05
- [Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…](https://intel.threadlinqs.com/threat/TL-2026-2280) — medium — 2026-08-28
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…](https://intel.threadlinqs.com/threat/TL-2026-2107) — critical — 2026-08-22
- [Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)](https://intel.threadlinqs.com/threat/TL-2026-2009) — medium — 2026-08-13
- ["City-Forum" Campaign Mass-Enumerates Salesforce Experience Cloud and ServiceNow Portals via Guest Access](https://intel.threadlinqs.com/threat/TL-2026-1999) — high — 2026-08-12
- [Metabase Unauthenticated SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) Exploited to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1980) — critical — 2026-08-10
- [AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…](https://intel.threadlinqs.com/threat/TL-2026-1963) — high — 2026-08-09
- [UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…](https://intel.threadlinqs.com/threat/TL-2026-1959) — critical — 2026-08-09
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…](https://intel.threadlinqs.com/threat/TL-2026-1930) — high — 2026-08-07
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…](https://intel.threadlinqs.com/threat/TL-2026-1872) — critical — 2026-08-04
- [CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB Database](https://intel.threadlinqs.com/threat/TL-2026-1802) — critical — 2026-07-31
- [ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades…](https://intel.threadlinqs.com/threat/TL-2026-1788) — medium — 2026-07-31
- [CosmosEscape: Platform-Wide Cosmos Master Key Exposure via Gremlin API Sandbox Escape in Azure Cosmos DB](https://intel.threadlinqs.com/threat/TL-2026-1784) — critical — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [CosmosEscape: Azure Cosmos DB Gremlin Sandbox Escape Exposed Platform-Wide Master Key (CVE-2026-66803)](https://intel.threadlinqs.com/threat/TL-2026-1779) — critical — 2026-07-30
- [CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-1755) — critical — 2026-07-29
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags…](https://intel.threadlinqs.com/threat/TL-2026-1735) — medium — 2026-07-28
- [AgentForger: Cross-Site Agent Forgery in ChatGPT Workspace Agent Builder](https://intel.threadlinqs.com/threat/TL-2026-1713) — critical — 2026-07-27
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26

## Related CVEs

CVEs referenced by the tracked threats that use T1526, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-42208](https://intel.threadlinqs.com/cve/CVE-2026-42208)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-39935](https://intel.threadlinqs.com/cve/CVE-2021-39935)
- [CVE-2022-0543](https://intel.threadlinqs.com/cve/CVE-2022-0543)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2025-11953](https://intel.threadlinqs.com/cve/CVE-2025-11953)
- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-3648](https://intel.threadlinqs.com/cve/CVE-2025-3648)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2025-49844](https://intel.threadlinqs.com/cve/CVE-2025-49844)
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)

## Detection coverage

Threadlinqs maintains 124 detection rules mapped to T1526 (SPL 39, KQL 49, Sigma 36). Rule content is available to Blue tier accounts and above; this page shows counts only.

124 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1526
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
