# T1556.006 Multi-Factor Authentication

> As of 2026-10-05, T1556.006 (Multi-Factor Authentication) appears in 22 tracked threats, first reported 2025-10-13 and most recently 2026-09-13, with linked actors including Scattered Spider, ShinyHunters, APT28; it most often appears alongside T1078.004 (Cloud Accounts).

- **Tracked threats:** 22 (7 critical, 15 high)
- **First seen:** 2025-10-13
- **Last seen:** 2026-09-13
- **Threat actors:** 18
- **Detection rules:** 50 (counts only; Blue tier and above)

## Key facts

- **ID:** T1556.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Defense Impairment, Credential Access
- **Matrix:** Enterprise
- **Parent:** T1556
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1556/006/

## Activity timeline

T1556.006 first appeared in tracked threats on 2025-10-13 and was most recently reported on 2026-09-13. The busiest month was 2026-07 with 6 reports, and 22 of the 22 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1556.006 Multi-Factor Authentication is catalogued by MITRE ATT&CK under the Persistence and Defense Impairment and Credential Access tactics in the Enterprise matrix, as a sub-technique of [T1556 Modify Authentication Process](https://intel.threadlinqs.com/technique/T1556). Threadlinqs maps 22 of 2623 tracked threats (0.8%) to it; by severity that is 7 critical, 15 high.

Threats that use T1556.006 most often also use [T1078.004 Cloud Accounts](https://intel.threadlinqs.com/technique/T1078.004) (15 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (13 threats), [T1539 Steal Web Session Cookie](https://intel.threadlinqs.com/technique/T1539) (11 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (11 threats), [T1199 Trusted Relationship](https://intel.threadlinqs.com/technique/T1199) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

18 tracked threat actors appear in the threats that use T1556.006; the most frequent are [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (4), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (3), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) (1), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1556.006.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1556.006, per MITRE ATT&CK.

- Active Directory — Active Directory Object Modification
- Application Log — Application Log Content
- Logon Session — Logon Session Creation
- User Account — User Account Authentication, User Account Modification

## Threat actors using it

- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) — 1
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 1
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 1
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 1
- [Storm-1167](https://intel.threadlinqs.com/actor/Storm-1167) — 1
- [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) — 1

## Tracked threats

22 tracked threats use T1556.006.

- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of…](https://intel.threadlinqs.com/threat/TL-2026-2026) — high — 2026-08-16
- [Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise](https://intel.threadlinqs.com/threat/TL-2026-1970) — high — 2026-08-10
- [Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra ID](https://intel.threadlinqs.com/threat/TL-2026-1952) — high — 2026-08-09
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1871) — high — 2026-08-04
- [Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication](https://intel.threadlinqs.com/threat/TL-2026-1842) — critical — 2026-08-03
- [Operation RoundPress: TA458 Deploys SpyPress Malware via Half-Click Webmail Zero-Days (CVE-2025-27915…](https://intel.threadlinqs.com/threat/TL-2026-2579) — critical — 2026-07-23
- ["The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…](https://intel.threadlinqs.com/threat/TL-2026-1593) — high — 2026-07-21
- [Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack](https://intel.threadlinqs.com/threat/TL-2026-1429) — high — 2026-07-17
- [Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and…](https://intel.threadlinqs.com/threat/TL-2026-1347) — high — 2026-07-15
- [Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1161) — high — 2026-07-10
- [BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1060) — high — 2026-07-02
- [Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public…](https://intel.threadlinqs.com/threat/TL-2026-0878) — high — 2026-06-19
- [Dashlane Device-Registration API 2FA OTP Brute-Force Campaign — Encrypted Vaults of <20 Personal-Plan…](https://intel.threadlinqs.com/threat/TL-2026-0705) — high — 2026-06-07
- [Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0560) — high — 2026-05-22
- [Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0529) — critical — 2026-05-19
- [Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers…](https://intel.threadlinqs.com/threat/TL-2026-0449) — critical — 2026-05-02
- [Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation…](https://intel.threadlinqs.com/threat/TL-2026-0266) — critical — 2026-03-21
- [ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-0054) — high — 2026-02-03
- [Swiss NCSC/NTC Pilot Project Discloses Multiple Vulnerabilities in TYPO3 CMS and QGIS/QWC2 (CVE-2025-30083…](https://intel.threadlinqs.com/threat/TL-2026-2450) — critical — 2025-10-13

## Related CVEs

CVEs referenced by the tracked threats that use T1556.006, most frequent first.

- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2025-27915](https://intel.threadlinqs.com/cve/CVE-2025-27915)
- [CVE-2025-3929](https://intel.threadlinqs.com/cve/CVE-2025-3929)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2025-62554](https://intel.threadlinqs.com/cve/CVE-2025-62554)
- [CVE-2025-62557](https://intel.threadlinqs.com/cve/CVE-2025-62557)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-34348](https://intel.threadlinqs.com/cve/CVE-2026-34348)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-8496](https://intel.threadlinqs.com/cve/CVE-2026-8496)

## Detection coverage

Threadlinqs maintains 50 detection rules mapped to T1556.006 (SPL 19, KQL 14, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

50 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1556 Modify Authentication Process](https://intel.threadlinqs.com/technique/T1556) — 147 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1556.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
