# T1552.005 Cloud Instance Metadata API

> As of 2026-10-05, T1552.005 (Cloud Instance Metadata API) appears in 53 tracked threats, first reported 2026-02-03 and most recently 2026-10-03, with linked actors including TeamPCP, Mini Shai-Hulud, BonJoviGoesHard; it most often appears alongside T1552.001 (Credentials In Files).

- **Tracked threats:** 53 (33 critical, 17 high, 2 medium)
- **First seen:** 2026-02-03
- **Last seen:** 2026-10-03
- **Threat actors:** 9
- **Detection rules:** 103 (counts only; Blue tier and above)

## Key facts

- **ID:** T1552.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1552
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1552/005/

## Activity timeline

T1552.005 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-10-03. The busiest month was 2026-05 with 15 reports, and 53 of the 53 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1552.005 Cloud Instance Metadata API is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552). Threadlinqs maps 53 of 2623 tracked threats (2%) to it; by severity that is 33 critical, 17 high, 2 medium.

Threats that use T1552.005 most often also use [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (47 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (39 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (37 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (33 threats), [T1526 Cloud Service Discovery](https://intel.threadlinqs.com/technique/T1526) (30 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1552.005; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (17), [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) (3), [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) (2), [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) (2), [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1552.005.

- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1552.005, per MITRE ATT&CK.

- User Account — User Account Authentication

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 17
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 3
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 2
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 2
- [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) — 1
- [GlassWorm Operators](https://intel.threadlinqs.com/actor/GlassWorm%20Operators) — 1
- [Miasma operator](https://intel.threadlinqs.com/actor/Miasma%20operator) — 1
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1
- [UNC6780](https://intel.threadlinqs.com/actor/UNC6780) — 1

## Tracked threats

The 30 most recent of 53 tracked threats that use T1552.005.

- [AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2860) — critical — 2026-10-03
- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — high — 2026-09-30
- [npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm](https://intel.threadlinqs.com/threat/TL-2026-2193) — critical — 2026-08-28
- [Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBI](https://intel.threadlinqs.com/threat/TL-2026-2186) — critical — 2026-08-28
- [StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…](https://intel.threadlinqs.com/threat/TL-2026-2160) — 2026-08-25
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…](https://intel.threadlinqs.com/threat/TL-2026-2107) — critical — 2026-08-22
- [CVE-2026-64849 — MLflow Server-Side Request Forgery (SSRF) Vulnerability in Model Registry Webhooks](https://intel.threadlinqs.com/threat/TL-2026-2077) — critical — 2026-08-19
- [Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer Stations](https://intel.threadlinqs.com/threat/TL-2026-1911) — high — 2026-08-06
- ['ChainDrop' self-propagating worm compromises hundreds of popular npm packages (keyv, cacheable ecosystem)…](https://intel.threadlinqs.com/threat/TL-2026-2822) — critical — 2026-08-04
- [ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…](https://intel.threadlinqs.com/threat/TL-2026-1872) — critical — 2026-08-04
- [Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)](https://intel.threadlinqs.com/threat/TL-2026-1861) — critical — 2026-08-04
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…](https://intel.threadlinqs.com/threat/TL-2026-1379) — high — 2026-07-15
- [AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Framework](https://intel.threadlinqs.com/threat/TL-2026-1360) — critical — 2026-07-15
- [npm Supply-Chain Attack on @asyncapi Packages Deploys Miasma Botnet via IPFS-Hosted Second-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1293) — high — 2026-07-14
- [Internet-Wide Reconnaissance Scans Target MCP Servers and Claude/Cursor AI-Agent Credentials](https://intel.threadlinqs.com/threat/TL-2026-1278) — medium — 2026-07-13
- [FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022…](https://intel.threadlinqs.com/threat/TL-2026-1209) — high — 2026-07-11
- [Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…](https://intel.threadlinqs.com/threat/TL-2026-1242) — high — 2026-06-26
- [Amazon Q Developer Extension Trust-Boundary & Symlink Flaws (CVE-2026-12957, CVE-2026-12958) Auto-Execute…](https://intel.threadlinqs.com/threat/TL-2026-0950) — high — 2026-06-26
- [Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-0979) — critical — 2026-06-12
- [CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710…](https://intel.threadlinqs.com/threat/TL-2026-0738) — critical — 2026-06-09
- [Miasma Worm Compromises 73 Microsoft GitHub Repositories Across Azure, Azure-Samples, Microsoft &…](https://intel.threadlinqs.com/threat/TL-2026-0719) — critical — 2026-06-08
- [Shai-Hulud "Hades" Miasma Worm — New PyPI Wave: 37 Malicious Wheels Across 19 Packages Abuse *-setup.pth…](https://intel.threadlinqs.com/threat/TL-2026-0709) — critical — 2026-06-07
- [vpmdhaj npm Supply Chain Attack — 14 OpenSearch/ElasticSearch Typosquats Steal AWS/Vault/CI-CD Secrets via…](https://intel.threadlinqs.com/threat/TL-2026-0623) — high — 2026-05-29
- [First AI-Agent-Driven Cloud Intrusion — Marimo CVE-2026-39987 RCE → AWS Secrets Manager → SSH Bastion →…](https://intel.threadlinqs.com/threat/TL-2026-0619) — high — 2026-05-28
- [Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container…](https://intel.threadlinqs.com/threat/TL-2026-0602) — high — 2026-05-27
- [durabletask PyPI Supply Chain Compromise (v1.4.1–1.4.3) — Microsoft-Published Azure Durable Functions SDK…](https://intel.threadlinqs.com/threat/TL-2026-0580) — critical — 2026-05-25
- [Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…](https://intel.threadlinqs.com/threat/TL-2026-0548) — critical — 2026-05-21
- [Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…](https://intel.threadlinqs.com/threat/TL-2026-0547) — critical — 2026-05-21

## Related CVEs

CVEs referenced by the tracked threats that use T1552.005, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2021-39935](https://intel.threadlinqs.com/cve/CVE-2021-39935)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2026-12957](https://intel.threadlinqs.com/cve/CVE-2026-12957)
- [CVE-2026-12958](https://intel.threadlinqs.com/cve/CVE-2026-12958)
- [CVE-2026-1357](https://intel.threadlinqs.com/cve/CVE-2026-1357)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-25592](https://intel.threadlinqs.com/cve/CVE-2026-25592)
- [CVE-2026-26030](https://intel.threadlinqs.com/cve/CVE-2026-26030)
- [CVE-2026-27771](https://intel.threadlinqs.com/cve/CVE-2026-27771)
- [CVE-2026-33032](https://intel.threadlinqs.com/cve/CVE-2026-33032)
- [CVE-2026-33626](https://intel.threadlinqs.com/cve/CVE-2026-33626)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-42208](https://intel.threadlinqs.com/cve/CVE-2026-42208)
- [CVE-2026-42271](https://intel.threadlinqs.com/cve/CVE-2026-42271)
- [CVE-2026-48710](https://intel.threadlinqs.com/cve/CVE-2026-48710)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)

## Detection coverage

Threadlinqs maintains 103 detection rules mapped to T1552.005 (SPL 34, KQL 44, Sigma 25). Rule content is available to Blue tier accounts and above; this page shows counts only.

103 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) — 551 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1552.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
