# T1550 Use Alternate Authentication Material

> As of 2026-10-05, T1550 (Use Alternate Authentication Material) appears in 207 tracked threats, first reported 2026-01-27 and most recently 2026-10-02, with linked actors including ShinyHunters, Scattered LAPSUS$ Hunters, TeamPCP; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 207 (106 critical, 87 high, 12 medium, 1 low)
- **First seen:** 2026-01-27
- **Last seen:** 2026-10-02
- **Threat actors:** 76
- **Detection rules:** 116 (counts only; Blue tier and above)

## Key facts

- **ID:** T1550
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1550/

## Activity timeline

T1550 first appeared in tracked threats on 2026-01-27 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 72 reports, and 207 of the 207 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1550 Use Alternate Authentication Material is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 207 of 2623 tracked threats (7.9%) to it; by severity that is 106 critical, 87 high, 12 medium, 1 low.

Threats that use T1550 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (137 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (114 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (112 threats), [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) (101 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (97 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

76 tracked threat actors appear in the threats that use T1550; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (11), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (7), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (7), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (6), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (6).

## Mitigations

MITRE ATT&CK lists 7 mitigations for T1550.

- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)
- [M1015 Active Directory Configuration](https://attack.mitre.org/mitigations/M1015/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1036 Account Use Policies](https://attack.mitre.org/mitigations/M1036/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1550, per MITRE ATT&CK.

- Active Directory — Active Directory Credential Request
- Application Log — Application Log Content
- Logon Session — Logon Session Creation
- User Account — User Account Authentication
- Web Credential — Web Credential Usage

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 11
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 7
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 7
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 6
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 6
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 6
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 6
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 6
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 5
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 5
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 4
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 4

## Tracked threats

The 30 most recent of 207 tracked threats that use T1550.

- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…](https://intel.threadlinqs.com/threat/TL-2026-2851) — critical — 2026-10-02
- [CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)](https://intel.threadlinqs.com/threat/TL-2026-2816) — critical — 2026-09-30
- [CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe…](https://intel.threadlinqs.com/threat/TL-2026-2640) — critical — 2026-09-24
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…](https://intel.threadlinqs.com/threat/TL-2026-2573) — critical — 2026-09-18
- [Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing…](https://intel.threadlinqs.com/threat/TL-2026-2563) — critical — 2026-09-18
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Second-Order SQL Injection in All-in-One WP Migration and Backup Plugin (CVE-2026-19949) Exposes 5M+…](https://intel.threadlinqs.com/threat/TL-2026-2301) — high — 2026-09-02
- [ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via…](https://intel.threadlinqs.com/threat/TL-2026-2285) — critical — 2026-09-01
- ["Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay](https://intel.threadlinqs.com/threat/TL-2026-2276) — high — 2026-09-01
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer/AMOS) Hijacking Claude AI…](https://intel.threadlinqs.com/threat/TL-2026-2262) — high — 2026-08-31
- [ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodology](https://intel.threadlinqs.com/threat/TL-2026-2168) — high — 2026-08-27
- [Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…](https://intel.threadlinqs.com/threat/TL-2026-2170) — high — 2026-08-26
- [iAuthFlow V2 Phishing Toolkit Enrolls Attacker-Controlled Passkeys That Survive Password Resets](https://intel.threadlinqs.com/threat/TL-2026-2095) — high — 2026-08-21
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…](https://intel.threadlinqs.com/threat/TL-2026-2065) — critical — 2026-08-19
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [CVE-2025-55241: Microsoft Entra ID Actor Token Flaw Allowed Cross-Tenant Global Admin Impersonation](https://intel.threadlinqs.com/threat/TL-2026-1986) — critical — 2026-08-11
- [AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…](https://intel.threadlinqs.com/threat/TL-2026-1963) — high — 2026-08-09
- [UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…](https://intel.threadlinqs.com/threat/TL-2026-1959) — critical — 2026-08-09
- [Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer Stations](https://intel.threadlinqs.com/threat/TL-2026-1911) — high — 2026-08-06
- [Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via…](https://intel.threadlinqs.com/threat/TL-2026-1897) — critical — 2026-08-05
- [August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp…](https://intel.threadlinqs.com/threat/TL-2026-1891) — critical — 2026-08-05
- [Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre…](https://intel.threadlinqs.com/threat/TL-2026-1889) — 2026-08-05
- [Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials…](https://intel.threadlinqs.com/threat/TL-2026-1888) — high — 2026-08-05
- [ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…](https://intel.threadlinqs.com/threat/TL-2026-1883) — critical — 2026-08-05
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via…](https://intel.threadlinqs.com/threat/TL-2026-1863) — critical — 2026-08-04
- [Pass-ta-key Attacks Enable Malware to Hijack Google-Synced Passkeys via Chrome/TPM/Google Cloud…](https://intel.threadlinqs.com/threat/TL-2026-1852) — high — 2026-08-03
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for…](https://intel.threadlinqs.com/threat/TL-2026-1838) — critical — 2026-08-03

## Related CVEs

CVEs referenced by the tracked threats that use T1550, most frequent first.

- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-4368](https://intel.threadlinqs.com/cve/CVE-2026-4368)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-40372](https://intel.threadlinqs.com/cve/CVE-2026-40372)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2026-48558](https://intel.threadlinqs.com/cve/CVE-2026-48558)
- [CVE-2026-53409](https://intel.threadlinqs.com/cve/CVE-2026-53409)
- [CVE-2026-53410](https://intel.threadlinqs.com/cve/CVE-2026-53410)
- [CVE-2026-53411](https://intel.threadlinqs.com/cve/CVE-2026-53411)

## Detection coverage

Threadlinqs maintains 116 detection rules mapped to T1550 (SPL 36, KQL 42, Sigma 38). Rule content is available to Blue tier accounts and above; this page shows counts only.

116 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1550.001 Application Access Token](https://intel.threadlinqs.com/technique/T1550.001) — 98 tracked threats
- [T1550.002 Pass the Hash](https://intel.threadlinqs.com/technique/T1550.002) — 19 tracked threats
- T1550.003 Pass the Ticket — 7 tracked threats
- [T1550.004 Web Session Cookie](https://intel.threadlinqs.com/technique/T1550.004) — 50 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1550
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
