Threadlinqs IntelligenceStart free

ATT&CK techniqueLateral Movement

T1550 Use Alternate Authentication Material

Lateral MovementEnterprise

As of 2026-10-05, T1550 (Use Alternate Authentication Material) appears in 207 tracked threats, first reported 2026-01-27 and most recently 2026-10-02, with linked actors including ShinyHunters, Scattered LAPSUS$ Hunters, TeamPCP; it most often appears alongside T1078 (Valid Accounts).

Tracked threats
207106 critical, 87 high, 12 medium, 1 low
First seen
2026-01-27
Last seen
2026-10-02
Threat actors
76In the threats using it
Detection rules
116Blue tier and above

Data as of:

Activity timeline

T1550 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 72 reports, and 207 of the 207 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1550 Use Alternate Authentication Material is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 207 of 2623 tracked threats (7.9%) to it; by severity that is 106 critical, 87 high, 12 medium, 1 low.

Threats that use T1550 most often also use T1078 Valid Accounts (137 threats), T1059 Command and Scripting Interpreter (114 threats), T1190 Exploit Public-Facing Application (112 threats), T1552 Unsecured Credentials (101 threats), T1071 Application Layer Protocol (97 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

76 tracked threat actors appear in the threats that use T1550; the most frequent are ShinyHunters (11), Scattered LAPSUS$ Hunters (7), TeamPCP (7), Scattered Spider (6), The Com (6).

Mitigations

MITRE ATT&CK lists 7 mitigations for T1550.

Data sources

Telemetry that can reveal T1550, per MITRE ATT&CK.

  • Active Directory — Active Directory Credential Request
  • Application Log — Application Log Content
  • Logon Session — Logon Session Creation
  • User Account — User Account Authentication
  • Web Credential — Web Credential Usage

Threat actors using it

Tracked threats

The 30 most recent of 207 tracked threats that use T1550.

Detection coverage

Threadlinqs maintains 116 detection rules mapped to T1550 (SPL 36, KQL 42, Sigma 38). Rule content is available to Blue tier accounts and above; this page shows counts only.

116 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques