Activity timeline
T1528 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 131 reports, and 401 of the 401 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1528 Steal Application Access Token is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 401 of 2623 tracked threats (15.3%) to it; by severity that is 147 critical, 223 high, 25 medium, 2 low.
Threats that use T1528 most often also use T1005 Data from Local System (200 threats), T1027 Obfuscated Files or Information (190 threats), T1567 Exfiltration Over Web Service (174 threats), T1059 Command and Scripting Interpreter (170 threats), T1552 Unsecured Credentials (156 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
109 tracked threat actors appear in the threats that use T1528; the most frequent are TeamPCP (38), ShinyHunters (19), Scattered LAPSUS$ Hunters (8), Scattered Spider (7), APT38 (6).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1528.
Data sources
Telemetry that can reveal T1528, per MITRE ATT&CK.
- Active Directory — Active Directory Object Modification
- User Account — User Account Modification
Threat actors using it
Tracked threats
The 30 most recent of 401 tracked threats that use T1528.
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…critical
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…high
- AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…critical
- Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and…high
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)high
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…medium
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)high
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)high
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplacemedium
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealerhigh
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…high
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…critical
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)high
- TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…high
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injectionmedium
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…high
- Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chainhigh
- AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Accesshigh
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…high
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EUhigh
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capabilityhigh
Detection coverage
Threadlinqs maintains 650 detection rules mapped to T1528 (SPL 224, KQL 246, Sigma 180). Rule content is available to Blue tier accounts and above; this page shows counts only.