Activity timeline
T1555.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1555.004 Windows Credential Manager is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1555 Credentials from Password Stores. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 13 high.
Threats that use T1555.004 most often also use T1005 Data from Local System (9 threats), T1555.003 Credentials from Web Browsers (8 threats), T1552.001 Credentials In Files (7 threats), T1685 Disable or Modify Tools (7 threats), T1027 Obfuscated Files or Information (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1555.004; the most frequent are Cavern Manticore (2), Nightmare Eclipse (2), APT34 (1), Chaotic Eclipse (1), Hyadina (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1555.004.
Data sources
Telemetry that can reveal T1555.004, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
13 tracked threats use T1555.004.
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…high
- Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin…high
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…high
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…high
- Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…high
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…high
- Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applicationshigh
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…high
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…high
- GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driverhigh
- Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)high
- SEO Poisoning Campaign Impersonates Gemini CLI and Claude Code to Deliver In-Memory PowerShell Infostealer…high
Detection coverage
Threadlinqs maintains 18 detection rules mapped to T1555.004 (SPL 6, KQL 8, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1555 Credentials from Password Stores — 445 tracked threats at the technique level.