# T1552.004 Private Keys

> As of 2026-10-05, T1552.004 (Private Keys) appears in 75 tracked threats, first reported 2026-02-16 and most recently 2026-10-02, with linked actors including TeamPCP, ShinyHunters, APT38; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 75 (44 critical, 27 high, 3 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-02
- **Threat actors:** 19
- **Detection rules:** 206 (counts only; Blue tier and above)

## Key facts

- **ID:** T1552.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1552
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1552/004/

## Activity timeline

T1552.004 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 19 reports, and 75 of the 75 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1552.004 Private Keys is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552). Threadlinqs maps 75 of 2623 tracked threats (2.9%) to it; by severity that is 44 critical, 27 high, 3 medium.

Threats that use T1552.004 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (52 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (48 threats), [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (47 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (37 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (31 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

19 tracked threat actors appear in the threats that use T1552.004; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (8), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (3), [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (2), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (2).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1552.004.

- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1552.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 8
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 2
- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) — 1

## Tracked threats

The 30 most recent of 75 tracked threats that use T1552.004.

- [GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)](https://intel.threadlinqs.com/threat/TL-2026-2846) — critical — 2026-10-02
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…](https://intel.threadlinqs.com/threat/TL-2026-2673) — high — 2026-09-26
- [ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Site](https://intel.threadlinqs.com/threat/TL-2026-2671) — critical — 2026-09-26
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…](https://intel.threadlinqs.com/threat/TL-2026-2514) — high — 2026-09-15
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…](https://intel.threadlinqs.com/threat/TL-2026-2442) — critical — 2026-09-11
- [Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…](https://intel.threadlinqs.com/threat/TL-2026-2373) — critical — 2026-09-07
- [Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception](https://intel.threadlinqs.com/threat/TL-2026-2294) — high — 2026-09-02
- [CVE-2026-0768: Critical Langflow RCE Vulnerability Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2270) — critical — 2026-09-01
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…](https://intel.threadlinqs.com/threat/TL-2026-2196) — critical — 2026-08-28
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…](https://intel.threadlinqs.com/threat/TL-2026-2153) — high — 2026-08-26
- [VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KB](https://intel.threadlinqs.com/threat/TL-2026-2116) — high — 2026-08-22
- [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://intel.threadlinqs.com/threat/TL-2026-2099) — critical — 2026-08-21
- [AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…](https://intel.threadlinqs.com/threat/TL-2026-2070) — critical — 2026-08-19
- [Coldcard Hardware Wallet $111M Bitcoin Theft: Weak RNG Private Key Vulnerability (Yasmarang PRNG Fallback)](https://intel.threadlinqs.com/threat/TL-2026-1992) — critical — 2026-08-12
- [Claude Code RCE via Malicious .mcp.json in Pull Request Branches](https://intel.threadlinqs.com/threat/TL-2026-1929) — high — 2026-08-07
- [Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1904) — critical — 2026-08-05
- [Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)](https://intel.threadlinqs.com/threat/TL-2026-1876) — medium — 2026-08-04
- [ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…](https://intel.threadlinqs.com/threat/TL-2026-1872) — critical — 2026-08-04
- [TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Repos](https://intel.threadlinqs.com/threat/TL-2026-1859) — high — 2026-08-04
- [Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication](https://intel.threadlinqs.com/threat/TL-2026-1842) — critical — 2026-08-03
- [Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1835) — critical — 2026-08-03
- [Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses](https://intel.threadlinqs.com/threat/TL-2026-1829) — critical — 2026-08-03

## Related CVEs

CVEs referenced by the tracked threats that use T1552.004, most frequent first.

- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-8963](https://intel.threadlinqs.com/cve/CVE-2024-8963)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2025-49704](https://intel.threadlinqs.com/cve/CVE-2025-49704)
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-34348](https://intel.threadlinqs.com/cve/CVE-2026-34348)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-42608](https://intel.threadlinqs.com/cve/CVE-2026-42608)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)

## Detection coverage

Threadlinqs maintains 206 detection rules mapped to T1552.004 (SPL 72, KQL 72, Sigma 60, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

206 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) — 551 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1552.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
