# T1552.007 Container API

> As of 2026-10-05, T1552.007 (Container API) appears in 15 tracked threats, first reported 2026-04-11 and most recently 2026-10-02, with linked actors including TeamPCP, UNC1069, APT38; it most often appears alongside T1552.001 (Credentials In Files).

- **Tracked threats:** 15 (10 critical, 5 high)
- **First seen:** 2026-04-11
- **Last seen:** 2026-10-02
- **Threat actors:** 8
- **Detection rules:** 32 (counts only; Blue tier and above)

## Key facts

- **ID:** T1552.007
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1552
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1552/007/

## Activity timeline

T1552.007 first appeared in tracked threats on 2026-04-11 and was most recently reported on 2026-10-02. The busiest month was 2026-04 with 4 reports, and 15 of the 15 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1552.007 Container API is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552). Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 10 critical, 5 high.

Threats that use T1552.007 most often also use [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (13 threats), [T1059.006 Python](https://intel.threadlinqs.com/technique/T1059.006) (9 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (9 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1552.007; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (3), [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) (1), [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1552.007.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)

## Data sources

Telemetry that can reveal T1552.007, per MITRE ATT&CK.

- Command — Command Execution
- User Account — User Account Authentication

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 1
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 1
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1

## Tracked threats

15 tracked threats use T1552.007.

- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…](https://intel.threadlinqs.com/threat/TL-2026-2851) — critical — 2026-10-02
- [AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2076) — critical — 2026-08-19
- [AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape…](https://intel.threadlinqs.com/threat/TL-2026-2030) — high — 2026-08-16
- ['ChainDrop' self-propagating worm compromises hundreds of popular npm packages (keyv, cacheable ecosystem)…](https://intel.threadlinqs.com/threat/TL-2026-2822) — critical — 2026-08-04
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022…](https://intel.threadlinqs.com/threat/TL-2026-1209) — high — 2026-07-11
- [Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host…](https://intel.threadlinqs.com/threat/TL-2026-0694) — critical — 2026-06-06
- [Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container…](https://intel.threadlinqs.com/threat/TL-2026-0602) — high — 2026-05-27
- [Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator…](https://intel.threadlinqs.com/threat/TL-2026-0515) — high — 2026-05-14
- [Mini Shai-Hulud v3 — TanStack/UiPath/Mistral AI npm & PyPI Supply Chain Compromise (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-0499) — critical — 2026-05-12
- [PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182…](https://intel.threadlinqs.com/threat/TL-2026-0478) — critical — 2026-05-07
- [Xinference PyPI Supply Chain Compromise — TeamPCP-Marked Credential Harvester (v2.6.0–2.6.2)](https://intel.threadlinqs.com/threat/TL-2026-0438) — critical — 2026-04-30
- [Bissa Scanner — AI-Assisted Mass Exploitation of CVE-2025-55182 (React Server Components RCE) and…](https://intel.threadlinqs.com/threat/TL-2026-0428) — critical — 2026-04-27
- [Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT…](https://intel.threadlinqs.com/threat/TL-2026-0397) — critical — 2026-04-20
- [Axios npm Supply Chain Compromise (v1.14.1 / v0.30.4) Reaches OpenAI macOS Signing Pipeline, Forces Apple…](https://intel.threadlinqs.com/threat/TL-2026-0351) — critical — 2026-04-11

## Related CVEs

CVEs referenced by the tracked threats that use T1552.007, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2020-15791](https://intel.threadlinqs.com/cve/CVE-2020-15791)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2026-1357](https://intel.threadlinqs.com/cve/CVE-2026-1357)
- [CVE-2026-27771](https://intel.threadlinqs.com/cve/CVE-2026-27771)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-51218](https://intel.threadlinqs.com/cve/CVE-2026-51218)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)
- [CVE-2026-66014](https://intel.threadlinqs.com/cve/CVE-2026-66014)

## Detection coverage

Threadlinqs maintains 32 detection rules mapped to T1552.007 (SPL 13, KQL 13, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

32 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) — 551 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1552.007
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
