Activity timeline
T1538 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 11 reports, and 28 of the 28 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1538 Cloud Service Dashboard is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 28 of 2623 tracked threats (1.1%) to it; by severity that is 6 critical, 18 high, 3 medium.
Threats that use T1538 most often also use T1078 Valid Accounts (18 threats), T1530 Data from Cloud Storage (16 threats), T1199 Trusted Relationship (15 threats), T1213 Data from Information Repositories (15 threats), T1087 Account Discovery (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
20 tracked threat actors appear in the threats that use T1538; the most frequent are ShinyHunters (5), Scattered LAPSUS$ Hunters (4), The Com (4), Scattered Spider (3), UNC6040 (3).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1538.
Data sources
Telemetry that can reveal T1538, per MITRE ATT&CK.
- Logon Session — Logon Session Creation
- User Account — User Account Authentication
Threat actors using it
Tracked threats
28 tracked threats use T1538.
- TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentialsmedium
- Unauthenticated SQL Injection Zero-Day in Metabase (CVSS 10.0, GHSA-vwf4-m7j8-wcjf) Exploited to Steal…critical
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…high
- CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code…critical
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accountshigh
- Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…high
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass…high
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK Publish Joint Guidance: Establishing a Coordinated Vulnerability…
- Forg365 Phishing-as-a-Service Targets Microsoft 365 via Device Code and AitM Session Thefthigh
- Everest Ransomware: Triple Extortion via Encryption, Access Brokering, and Insider Recruitmenthigh
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…high
- ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens…high
- Cloud Bucket Hijacking — Global Namespace Risk: Silent Data-Stream Redirection via Statically-Named Storage…critical
- FIFA World Cup 2026 Broadcast API Broken Access Control (Missing Server-Side Authorization) Allowed Live TV…high
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated…high
- Void Blizzard (LAUNDRY BEAR) Russian State-Sponsored Cloud-Espionage Actor — Russian National Denis…high
- Nimbus RAT: Java-based Remote Access Trojan Delivered via Microsoft Teams Vishing, Quick Assist, and Google…high
- Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…critical
- Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltrationcritical
- NVIDIA GeForce NOW Armenian Data Breach via GFN.am Alliance Partner Compromise — ShinyHunters-Branded PII…high
- ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330…high
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypasshigh
- Active Scanning for Exposed Anthropic API Endpointsmedium
- Anthropic API Scanning Campaign - Targeting Self-Hosted LLM Infrastructuremedium
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineeringcritical
Detection coverage
Threadlinqs maintains 18 detection rules mapped to T1538 (SPL 5, KQL 7, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.