# T1555.005 Password Managers

> As of 2026-10-05, T1555.005 (Password Managers) appears in 25 tracked threats, first reported 2026-02-17 and most recently 2026-09-29, with linked actors including ClickLock Dev, TeamPCP, ALPHV; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 25 (5 critical, 17 high, 3 medium)
- **First seen:** 2026-02-17
- **Last seen:** 2026-09-29
- **Threat actors:** 17
- **Detection rules:** 50 (counts only; Blue tier and above)

## Key facts

- **ID:** T1555.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1555
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1555/005/

## Activity timeline

T1555.005 first appeared in tracked threats on 2026-02-17 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 12 reports, and 25 of the 25 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1555.005 Password Managers is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1555 Credentials from Password Stores](https://intel.threadlinqs.com/technique/T1555). Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 5 critical, 17 high, 3 medium.

Threats that use T1555.005 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (23 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (18 threats), [T1555.003 Credentials from Web Browsers](https://intel.threadlinqs.com/technique/T1555.003) (17 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (16 threats), [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

17 tracked threat actors appear in the threats that use T1555.005; the most frequent are [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (2), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (2), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (1), [AMOS Operators](https://intel.threadlinqs.com/actor/AMOS%20Operators) (1), [APT28](https://intel.threadlinqs.com/actor/APT28) (1).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1555.005.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1555.005, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Process — OS API Execution, Process Access

## Threat actors using it

- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 2
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [AMOS Operators](https://intel.threadlinqs.com/actor/AMOS%20Operators) — 1
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 1
- [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) — 1

## Tracked threats

25 tracked threats use T1555.005.

- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…](https://intel.threadlinqs.com/threat/TL-2026-2387) — critical — 2026-09-08
- [Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)](https://intel.threadlinqs.com/threat/TL-2026-1886) — high — 2026-08-05
- [Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)](https://intel.threadlinqs.com/threat/TL-2026-1876) — medium — 2026-08-04
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applications](https://intel.threadlinqs.com/threat/TL-2026-1698) — high — 2026-07-25
- [CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs)](https://intel.threadlinqs.com/threat/TL-2026-1470) — medium — 2026-07-18
- [ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…](https://intel.threadlinqs.com/threat/TL-2026-1440) — high — 2026-07-17
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet…](https://intel.threadlinqs.com/threat/TL-2026-1394) — medium — 2026-07-16
- [MacSync Stealer: 'ClaudeFix' Malvertising Campaign Abuses Shared Claude Chat Links to Deploy macOS Infostealer](https://intel.threadlinqs.com/threat/TL-2026-1384) — high — 2026-07-15
- [Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…](https://intel.threadlinqs.com/threat/TL-2026-1379) — high — 2026-07-15
- [OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)](https://intel.threadlinqs.com/threat/TL-2026-1363) — critical — 2026-07-15
- [CrashStealer: Notarized Fake Apple CrashReporter App Steals macOS Keychain, Browser, and Crypto Wallet…](https://intel.threadlinqs.com/threat/TL-2026-1358) — high — 2026-07-15
- [Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecraft](https://intel.threadlinqs.com/threat/TL-2026-1333) — high — 2026-07-14
- [Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and…](https://intel.threadlinqs.com/threat/TL-2026-1080) — high — 2026-07-02
- [Meow Mac Stealer RAT: macOS ClickFix Lures Deploy AppleScript Infostealer with Persistent RAT Capabilities](https://intel.threadlinqs.com/threat/TL-2026-0842) — high — 2026-06-17
- [AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202…](https://intel.threadlinqs.com/threat/TL-2026-0745) — high — 2026-06-10
- [VaultJacking — Google Password Manager Vault Theft via Single Captured 6-Digit PIN (PhishU Framework)](https://intel.threadlinqs.com/threat/TL-2026-0620) — high — 2026-05-28
- [Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…](https://intel.threadlinqs.com/threat/TL-2026-0547) — critical — 2026-05-21
- [Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator…](https://intel.threadlinqs.com/threat/TL-2026-0515) — high — 2026-05-14
- [OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relay](https://intel.threadlinqs.com/threat/TL-2026-0480) — high — 2026-05-07
- [KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026)](https://intel.threadlinqs.com/threat/TL-2026-0416) — critical — 2026-04-23
- [Malicious OpenClaw Skills — AMOS macOS Stealer Supply Chain via ClawHub, SkillsMP, and GitHub](https://intel.threadlinqs.com/threat/TL-2026-0136) — critical — 2026-02-24
- [25 Zero-Knowledge Bypass Vulnerabilities in Cloud Password Managers (Bitwarden/LastPass/Dashlane) — ETH…](https://intel.threadlinqs.com/threat/TL-2026-0122) — high — 2026-02-17

## Related CVEs

CVEs referenced by the tracked threats that use T1555.005, most frequent first.

- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)

## Detection coverage

Threadlinqs maintains 50 detection rules mapped to T1555.005 (SPL 13, KQL 19, Sigma 18). Rule content is available to Blue tier accounts and above; this page shows counts only.

50 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1555 Credentials from Password Stores](https://intel.threadlinqs.com/technique/T1555) — 445 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1555.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
