# T1550.002 Pass the Hash

> As of 2026-10-05, T1550.002 (Pass the Hash) appears in 19 tracked threats, first reported 2026-02-02 and most recently 2026-09-26, with linked actors including Cavern Manticore, Nightmare Eclipse, Nightmare-Eclipse; it most often appears alongside T1021.002 (SMB/Windows Admin Shares).

- **Tracked threats:** 19 (8 critical, 9 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-26
- **Threat actors:** 6
- **Detection rules:** 50 (counts only; Blue tier and above)

## Key facts

- **ID:** T1550.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Parent:** T1550
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1550/002/

## Activity timeline

T1550.002 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-26. The busiest month was 2026-07 with 7 reports, and 19 of the 19 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1550.002 Pass the Hash is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix, as a sub-technique of [T1550 Use Alternate Authentication Material](https://intel.threadlinqs.com/technique/T1550). Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 8 critical, 9 high, 2 medium.

Threats that use T1550.002 most often also use [T1021.002 SMB/Windows Admin Shares](https://intel.threadlinqs.com/technique/T1021.002) (11 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (11 threats), [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (9 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (9 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1550.002; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (1), [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) (1), [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) (1), [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1550.002.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)
- [M1052 User Account Control](https://attack.mitre.org/mitigations/M1052/)

## Data sources

Telemetry that can reveal T1550.002, per MITRE ATT&CK.

- Active Directory — Active Directory Credential Request
- Logon Session — Logon Session Creation
- User Account — User Account Authentication

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 1
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 1
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 1
- [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) — 1
- [UTA0533](https://intel.threadlinqs.com/actor/UTA0533) — 1

## Tracked threats

19 tracked threats use T1550.002.

- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk…](https://intel.threadlinqs.com/threat/TL-2026-1638) — critical — 2026-07-22
- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth…](https://intel.threadlinqs.com/threat/TL-2026-1382) — critical — 2026-07-15
- [LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…](https://intel.threadlinqs.com/threat/TL-2026-1373) — high — 2026-07-15
- [CVE-2026-45659: Microsoft SharePoint Deserialization RCE Actively Exploited, Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1068) — high — 2026-07-02
- [CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day Exploited In-the-Wild Against Ukrainian Entities…](https://intel.threadlinqs.com/threat/TL-2026-0761) — high — 2026-06-10
- [Unpatched Windows search: URI Handler NTLMv2 Hash Leak via crumb=location UNC Coercion (No CVE, Microsoft…](https://intel.threadlinqs.com/threat/TL-2026-0673) — high — 2026-06-03
- [SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and…](https://intel.threadlinqs.com/threat/TL-2026-0498) — critical — 2026-05-12
- [CVE-2026-32202 — Windows Shell Protection Mechanism Failure: NTLM Authentication Coercion via Auto-Parsed…](https://intel.threadlinqs.com/threat/TL-2026-0435) — critical — 2026-04-29
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [QEMU Virtualization Abuse for PayoutsKing Ransomware Delivery & Evasion](https://intel.threadlinqs.com/threat/TL-2026-0379) — high — 2026-04-16
- [AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55…](https://intel.threadlinqs.com/threat/TL-2026-0131) — critical — 2026-02-22
- [Microsoft NTLM Deprecation - Three-Stage Phase-Out Plan](https://intel.threadlinqs.com/threat/TL-2026-0040) — high — 2026-02-03
- [Microsoft NTLM Deprecation - Enterprise Migration Planning Required](https://intel.threadlinqs.com/threat/TL-2026-0018) — medium — 2026-02-02
- [Microsoft NTLM Phase-Out: Detection & Migration Guidance](https://intel.threadlinqs.com/threat/TL-2026-0009) — medium — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T1550.002, most frequent first.

- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-43451](https://intel.threadlinqs.com/cve/CVE-2024-43451)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-60167](https://intel.threadlinqs.com/cve/CVE-2026-60167)
- [CVE-2026-60168](https://intel.threadlinqs.com/cve/CVE-2026-60168)
- [CVE-2026-60169](https://intel.threadlinqs.com/cve/CVE-2026-60169)
- [CVE-2026-60170](https://intel.threadlinqs.com/cve/CVE-2026-60170)

## Detection coverage

Threadlinqs maintains 50 detection rules mapped to T1550.002 (SPL 13, KQL 23, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.

50 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1550 Use Alternate Authentication Material](https://intel.threadlinqs.com/technique/T1550) — 207 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1550.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
