Activity timeline
T1550 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 72 reports, and 207 of the 207 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1550 Use Alternate Authentication Material is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 207 of 2623 tracked threats (7.9%) to it; by severity that is 106 critical, 87 high, 12 medium, 1 low.
Threats that use T1550 most often also use T1078 Valid Accounts (137 threats), T1059 Command and Scripting Interpreter (114 threats), T1190 Exploit Public-Facing Application (112 threats), T1552 Unsecured Credentials (101 threats), T1071 Application Layer Protocol (97 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
76 tracked threat actors appear in the threats that use T1550; the most frequent are ShinyHunters (11), Scattered LAPSUS$ Hunters (7), TeamPCP (7), Scattered Spider (6), The Com (6).
Mitigations
MITRE ATT&CK lists 7 mitigations for T1550.
Data sources
Telemetry that can reveal T1550, per MITRE ATT&CK.
- Active Directory — Active Directory Credential Request
- Application Log — Application Log Content
- Logon Session — Logon Session Creation
- User Account — User Account Authentication
- Web Credential — Web Credential Usage
Threat actors using it
Tracked threats
The 30 most recent of 207 tracked threats that use T1550.
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…critical
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)critical
- CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe…critical
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing…critical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Second-Order SQL Injection in All-in-One WP Migration and Backup Plugin (CVE-2026-19949) Exposes 5M+…high
- ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via…critical
- "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relayhigh
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer/AMOS) Hijacking Claude AI…high
- ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodologyhigh
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…high
- iAuthFlow V2 Phishing Toolkit Enrolls Attacker-Controlled Passkeys That Survive Password Resetshigh
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…critical
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- CVE-2025-55241: Microsoft Entra ID Actor Token Flaw Allowed Cross-Tenant Global Admin Impersonationcritical
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…high
- UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…critical
- Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer Stationshigh
- Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via…critical
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp…critical
- Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre…
- Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials…high
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…critical
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via…critical
- Pass-ta-key Attacks Enable Malware to Hijack Google-Synced Passkeys via Chrome/TPM/Google Cloud…high
- CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for…critical
Detection coverage
Threadlinqs maintains 116 detection rules mapped to T1550 (SPL 36, KQL 42, Sigma 38). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1550.001 Application Access Token — 98 tracked threats
- T1550.002 Pass the Hash — 19 tracked threats
- T1550.003 Pass the Ticket — 7 tracked threats
- T1550.004 Web Session Cookie — 50 tracked threats