Activity timeline
T1550.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 31 reports, and 98 of the 98 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1550.001 Application Access Token is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix, as a sub-technique of T1550 Use Alternate Authentication Material. Threadlinqs maps 98 of 2623 tracked threats (3.7%) to it; by severity that is 37 critical, 57 high, 3 medium.
Threats that use T1550.001 most often also use T1528 Steal Application Access Token (67 threats), T1071.001 Web Protocols (43 threats), T1078.004 Cloud Accounts (43 threats), T1190 Exploit Public-Facing Application (39 threats), T1566.002 Spearphishing Link (39 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
31 tracked threat actors appear in the threats that use T1550.001; the most frequent are ShinyHunters (5), Cavern Manticore (3), EvilTokens (3), TeamPCP (3), Greatness PhaaS Operators (2).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1550.001.
Data sources
Telemetry that can reveal T1550.001, per MITRE ATT&CK.
- Web Credential — Web Credential Usage
Threat actors using it
Tracked threats
The 30 most recent of 98 tracked threats that use T1550.001.
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…high
- AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…critical
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…critical
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rowshigh
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…high
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…critical
- CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe…critical
- OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)high
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injectionmedium
- AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Accesshigh
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EUhigh
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capabilityhigh
- Coordinated GitHub API Enumeration and Access Token Abuse Campaignhigh
- CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After Disclosurecritical
- FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial…high
- Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV…critical
- Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…medium
- ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs…critical
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accountshigh
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…
- GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)critical
- CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…critical
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…high
- Suspected China-Linked Actor Runs Near-Autonomous Multi-Agent AI Attack on Taiwan Government, Nuclear Safety…critical
Detection coverage
Threadlinqs maintains 319 detection rules mapped to T1550.001 (SPL 113, KQL 123, Sigma 83). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1550 Use Alternate Authentication Material — 207 tracked threats at the technique level.