# T1528 Steal Application Access Token

> As of 2026-10-05, T1528 (Steal Application Access Token) appears in 401 tracked threats, first reported 2026-02-02 and most recently 2026-10-04, with linked actors including TeamPCP, ShinyHunters, Scattered LAPSUS$ Hunters; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 401 (147 critical, 223 high, 25 medium, 2 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-04
- **Threat actors:** 109
- **Detection rules:** 650 (counts only; Blue tier and above)

## Key facts

- **ID:** T1528
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1528/

## Activity timeline

T1528 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 131 reports, and 401 of the 401 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1528 Steal Application Access Token is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 401 of 2623 tracked threats (15.3%) to it; by severity that is 147 critical, 223 high, 25 medium, 2 low.

Threats that use T1528 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (200 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (190 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (174 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (170 threats), [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) (156 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

109 tracked threat actors appear in the threats that use T1528; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (38), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (19), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (8), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (7), [APT38](https://intel.threadlinqs.com/actor/APT38) (6).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1528.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1528, per MITRE ATT&CK.

- Active Directory — Active Directory Object Modification
- User Account — User Account Modification

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 38
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 19
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 8
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 7
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 6
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 6
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 6
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 6
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 6
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 6
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 6
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 5

## Tracked threats

The 30 most recent of 401 tracked threats that use T1528.

- [Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…](https://intel.threadlinqs.com/threat/TL-2026-2894) — critical — 2026-10-04
- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2873) — high — 2026-10-03
- [AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2860) — critical — 2026-10-03
- [Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and…](https://intel.threadlinqs.com/threat/TL-2026-2892) — high — 2026-10-02
- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — high — 2026-09-30
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…](https://intel.threadlinqs.com/threat/TL-2026-2770) — medium — 2026-09-29
- [Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)](https://intel.threadlinqs.com/threat/TL-2026-2757) — high — 2026-09-28
- [Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)](https://intel.threadlinqs.com/threat/TL-2026-2752) — high — 2026-09-28
- [TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace](https://intel.threadlinqs.com/threat/TL-2026-2715) — medium — 2026-09-27
- [ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer](https://intel.threadlinqs.com/threat/TL-2026-2699) — high — 2026-09-27
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…](https://intel.threadlinqs.com/threat/TL-2026-2661) — high — 2026-09-26
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-2680) — critical — 2026-09-25
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25
- [OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)](https://intel.threadlinqs.com/threat/TL-2026-2628) — high — 2026-09-23
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection](https://intel.threadlinqs.com/threat/TL-2026-2610) — medium — 2026-09-21
- [Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…](https://intel.threadlinqs.com/threat/TL-2026-2602) — high — 2026-09-21
- [Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain](https://intel.threadlinqs.com/threat/TL-2026-2601) — high — 2026-09-21
- [AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access](https://intel.threadlinqs.com/threat/TL-2026-2568) — high — 2026-09-18
- [Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…](https://intel.threadlinqs.com/threat/TL-2026-2566) — high — 2026-09-18
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EU](https://intel.threadlinqs.com/threat/TL-2026-2537) — high — 2026-09-16
- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability](https://intel.threadlinqs.com/threat/TL-2026-2468) — high — 2026-09-12

## Related CVEs

CVEs referenced by the tracked threats that use T1528, most frequent first.

- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2026-48710](https://intel.threadlinqs.com/cve/CVE-2026-48710)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2024-3094](https://intel.threadlinqs.com/cve/CVE-2024-3094)
- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-25592](https://intel.threadlinqs.com/cve/CVE-2026-25592)
- [CVE-2026-26030](https://intel.threadlinqs.com/cve/CVE-2026-26030)
- [CVE-2026-27690](https://intel.threadlinqs.com/cve/CVE-2026-27690)

## Detection coverage

Threadlinqs maintains 650 detection rules mapped to T1528 (SPL 224, KQL 246, Sigma 180). Rule content is available to Blue tier accounts and above; this page shows counts only.

650 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1528
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
