Activity timeline
T1552.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 19 reports, and 75 of the 75 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1552.004 Private Keys is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1552 Unsecured Credentials. Threadlinqs maps 75 of 2623 tracked threats (2.9%) to it; by severity that is 44 critical, 27 high, 3 medium.
Threats that use T1552.004 most often also use T1005 Data from Local System (52 threats), T1071.001 Web Protocols (48 threats), T1552.001 Credentials In Files (47 threats), T1082 System Information Discovery (37 threats), T1041 Exfiltration Over C2 Channel (31 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
19 tracked threat actors appear in the threats that use T1552.004; the most frequent are TeamPCP (8), ShinyHunters (3), APT38 (2), Andariel (2), Lazarus Group (2).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1552.004.
Data sources
Telemetry that can reveal T1552.004, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
Threat actors using it
Tracked threats
The 30 most recent of 75 tracked threats that use T1552.004.
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)critical
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitationcritical
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…high
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Sitecritical
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leakcritical
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…medium
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…high
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…critical
- Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interceptionhigh
- CVE-2026-0768: Critical Langflow RCE Vulnerability Under Active Exploitationcritical
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…critical
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…high
- VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KBhigh
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2critical
- AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…critical
- Coldcard Hardware Wallet $111M Bitcoin Theft: Weak RNG Private Key Vulnerability (Yasmarang PRNG Fallback)critical
- Claude Code RCE via Malicious .mcp.json in Pull Request Brancheshigh
- Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theftcritical
- Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)medium
- ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…critical
- TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Reposhigh
- Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authenticationcritical
- Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theftcritical
- Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addressescritical
Detection coverage
Threadlinqs maintains 206 detection rules mapped to T1552.004 (SPL 72, KQL 72, Sigma 60, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1552 Unsecured Credentials — 551 tracked threats at the technique level.