# T1555.004 Windows Credential Manager

> As of 2026-10-05, T1555.004 (Windows Credential Manager) appears in 13 tracked threats, first reported 2026-05-21 and most recently 2026-10-03, with linked actors including Cavern Manticore, Nightmare Eclipse, APT34; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 13 (13 high)
- **First seen:** 2026-05-21
- **Last seen:** 2026-10-03
- **Threat actors:** 8
- **Detection rules:** 18 (counts only; Blue tier and above)

## Key facts

- **ID:** T1555.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1555
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1555/004/

## Activity timeline

T1555.004 first appeared in tracked threats on 2026-05-21 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1555.004 Windows Credential Manager is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1555 Credentials from Password Stores](https://intel.threadlinqs.com/technique/T1555). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 13 high.

Threats that use T1555.004 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (9 threats), [T1555.003 Credentials from Web Browsers](https://intel.threadlinqs.com/technique/T1555.003) (8 threats), [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (7 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (7 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1555.004; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (2), [APT34](https://intel.threadlinqs.com/actor/APT34) (1), [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (1), [Hyadina](https://intel.threadlinqs.com/actor/Hyadina) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1555.004.

- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1555.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Process — OS API Execution, Process Creation

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 2
- [APT34](https://intel.threadlinqs.com/actor/APT34) — 1
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Hyadina](https://intel.threadlinqs.com/actor/Hyadina) — 1
- [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) — 1
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 1
- [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945) — 1

## Tracked threats

13 tracked threats use T1555.004.

- [Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…](https://intel.threadlinqs.com/threat/TL-2026-2868) — high — 2026-10-03
- [Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin…](https://intel.threadlinqs.com/threat/TL-2026-2648) — high — 2026-09-25
- [Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…](https://intel.threadlinqs.com/threat/TL-2026-2602) — high — 2026-09-21
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02
- [Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2108) — high — 2026-08-22
- [CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…](https://intel.threadlinqs.com/threat/TL-2026-1857) — high — 2026-08-04
- [Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applications](https://intel.threadlinqs.com/threat/TL-2026-1698) — high — 2026-07-25
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…](https://intel.threadlinqs.com/threat/TL-2026-1588) — high — 2026-07-21
- [LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…](https://intel.threadlinqs.com/threat/TL-2026-1373) — high — 2026-07-15
- [GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver](https://intel.threadlinqs.com/threat/TL-2026-1148) — high — 2026-07-09
- [Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)](https://intel.threadlinqs.com/threat/TL-2026-0743) — high — 2026-06-10
- [SEO Poisoning Campaign Impersonates Gemini CLI and Claude Code to Deliver In-Memory PowerShell Infostealer…](https://intel.threadlinqs.com/threat/TL-2026-0546) — high — 2026-05-21

## Detection coverage

Threadlinqs maintains 18 detection rules mapped to T1555.004 (SPL 6, KQL 8, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

18 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1555 Credentials from Password Stores](https://intel.threadlinqs.com/technique/T1555) — 445 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1555.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
