# T1538 Cloud Service Dashboard

> As of 2026-10-05, T1538 (Cloud Service Dashboard) appears in 28 tracked threats, first reported 2026-02-02 and most recently 2026-09-14, with linked actors including ShinyHunters, Scattered LAPSUS$ Hunters, The Com; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 28 (6 critical, 18 high, 3 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-14
- **Threat actors:** 20
- **Detection rules:** 18 (counts only; Blue tier and above)

## Key facts

- **ID:** T1538
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1538/

## Activity timeline

T1538 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-14. The busiest month was 2026-07 with 11 reports, and 28 of the 28 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1538 Cloud Service Dashboard is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 28 of 2623 tracked threats (1.1%) to it; by severity that is 6 critical, 18 high, 3 medium.

Threats that use T1538 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (18 threats), [T1530 Data from Cloud Storage](https://intel.threadlinqs.com/technique/T1530) (16 threats), [T1199 Trusted Relationship](https://intel.threadlinqs.com/technique/T1199) (15 threats), [T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213) (15 threats), [T1087 Account Discovery](https://intel.threadlinqs.com/technique/T1087) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

20 tracked threat actors appear in the threats that use T1538; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (5), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (4), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (4), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (3), [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) (3).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1538.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)

## Data sources

Telemetry that can reveal T1538, per MITRE ATT&CK.

- Logon Session — Logon Session Creation
- User Account — User Account Authentication

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 5
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 4
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 4
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 3
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 3
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 3
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 2
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 2
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 2
- [APT34](https://intel.threadlinqs.com/actor/APT34) — 1
- [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) — 1

## Tracked threats

28 tracked threats use T1538.

- [TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentials](https://intel.threadlinqs.com/threat/TL-2026-2491) — medium — 2026-09-14
- [Unauthenticated SQL Injection Zero-Day in Metabase (CVSS 10.0, GHSA-vwf4-m7j8-wcjf) Exploited to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1974) — critical — 2026-08-10
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…](https://intel.threadlinqs.com/threat/TL-2026-1930) — high — 2026-08-07
- [CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code…](https://intel.threadlinqs.com/threat/TL-2026-1893) — critical — 2026-08-05
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…](https://intel.threadlinqs.com/threat/TL-2026-1734) — high — 2026-07-28
- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — high — 2026-07-22
- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…](https://intel.threadlinqs.com/threat/TL-2026-1588) — high — 2026-07-21
- [Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1584) — high — 2026-07-21
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK Publish Joint Guidance: Establishing a Coordinated Vulnerability…](https://intel.threadlinqs.com/threat/TL-2026-1419) — 2026-07-16
- [Forg365 Phishing-as-a-Service Targets Microsoft 365 via Device Code and AitM Session Theft](https://intel.threadlinqs.com/threat/TL-2026-1280) — high — 2026-07-13
- [Everest Ransomware: Triple Extortion via Encryption, Access Brokering, and Insider Recruitment](https://intel.threadlinqs.com/threat/TL-2026-1172) — high — 2026-07-10
- [Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1161) — high — 2026-07-10
- [ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1036) — high — 2026-07-01
- [Cloud Bucket Hijacking — Global Namespace Risk: Silent Data-Stream Redirection via Statically-Named Storage…](https://intel.threadlinqs.com/threat/TL-2026-0952) — critical — 2026-06-27
- [FIFA World Cup 2026 Broadcast API Broken Access Control (Missing Server-Side Authorization) Allowed Live TV…](https://intel.threadlinqs.com/threat/TL-2026-0859) — high — 2026-06-16
- [Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated…](https://intel.threadlinqs.com/threat/TL-2026-0804) — high — 2026-06-15
- [Void Blizzard (LAUNDRY BEAR) Russian State-Sponsored Cloud-Espionage Actor — Russian National Denis…](https://intel.threadlinqs.com/threat/TL-2026-0796) — high — 2026-06-14
- [Nimbus RAT: Java-based Remote Access Trojan Delivered via Microsoft Teams Vishing, Quick Assist, and Google…](https://intel.threadlinqs.com/threat/TL-2026-0847) — high — 2026-05-28
- [Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…](https://intel.threadlinqs.com/threat/TL-2026-0548) — critical — 2026-05-21
- [Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0529) — critical — 2026-05-19
- [NVIDIA GeForce NOW Armenian Data Breach via GFN.am Alliance Partner Compromise — ShinyHunters-Branded PII…](https://intel.threadlinqs.com/threat/TL-2026-0485) — high — 2026-05-08
- [ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330…](https://intel.threadlinqs.com/threat/TL-2026-0482) — high — 2026-05-08
- [ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-0054) — high — 2026-02-03
- [Active Scanning for Exposed Anthropic API Endpoints](https://intel.threadlinqs.com/threat/TL-2026-0051) — medium — 2026-02-03
- [Anthropic API Scanning Campaign - Targeting Self-Hosted LLM Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0036) — medium — 2026-02-03
- [ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering](https://intel.threadlinqs.com/threat/TL-2026-0013) — critical — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T1538, most frequent first.

- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)

## Detection coverage

Threadlinqs maintains 18 detection rules mapped to T1538 (SPL 5, KQL 7, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

18 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1538
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
