Activity timeline
T1555.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 12 reports, and 25 of the 25 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1555.005 Password Managers is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1555 Credentials from Password Stores. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 5 critical, 17 high, 3 medium.
Threats that use T1555.005 most often also use T1071.001 Web Protocols (23 threats), T1005 Data from Local System (18 threats), T1555.003 Credentials from Web Browsers (17 threats), T1041 Exfiltration Over C2 Channel (16 threats), T1552.001 Credentials In Files (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
17 tracked threat actors appear in the threats that use T1555.005; the most frequent are ClickLock Dev (2), TeamPCP (2), ALPHV (1), AMOS Operators (1), APT28 (1).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1555.005.
Data sources
Telemetry that can reveal T1555.005, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Process — OS API Execution, Process Access
Threat actors using it
Tracked threats
25 tracked threats use T1555.005.
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…critical
- Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)high
- Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)medium
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applicationshigh
- CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs)medium
- ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…high
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoorhigh
- Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet…medium
- MacSync Stealer: 'ClaudeFix' Malvertising Campaign Abuses Shared Claude Chat Links to Deploy macOS Infostealerhigh
- Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…high
- OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)critical
- CrashStealer: Notarized Fake Apple CrashReporter App Steals macOS Keychain, Browser, and Crypto Wallet…high
- Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecrafthigh
- Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and…high
- Meow Mac Stealer RAT: macOS ClickFix Lures Deploy AppleScript Infostealer with Persistent RAT Capabilitieshigh
- AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202…high
- VaultJacking — Google Password Manager Vault Theft via Single Captured 6-Digit PIN (PhishU Framework)high
- Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…critical
- Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator…high
- OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relayhigh
- KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026)critical
- Malicious OpenClaw Skills — AMOS macOS Stealer Supply Chain via ClawHub, SkillsMP, and GitHubcritical
- 25 Zero-Knowledge Bypass Vulnerabilities in Cloud Password Managers (Bitwarden/LastPass/Dashlane) — ETH…high
Detection coverage
Threadlinqs maintains 50 detection rules mapped to T1555.005 (SPL 13, KQL 19, Sigma 18). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1555 Credentials from Password Stores — 445 tracked threats at the technique level.