# T1557.001 Name Resolution Poisoning and SMB Relay

> As of 2026-10-05, T1557.001 (Name Resolution Poisoning and SMB Relay) appears in 13 tracked threats, first reported 2026-02-02 and most recently 2026-09-01, with linked actors including The Gentlemen; it most often appears alongside T1187 (Forced Authentication).

- **Tracked threats:** 13 (5 critical, 7 high, 1 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-01
- **Threat actors:** 1
- **Detection rules:** 55 (counts only; Blue tier and above)

## Key facts

- **ID:** T1557.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access, Collection
- **Matrix:** Enterprise
- **Parent:** T1557
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1557/001/

## Activity timeline

T1557.001 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-01. The busiest month was 2026-07 with 4 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1557.001 Name Resolution Poisoning and SMB Relay is catalogued by MITRE ATT&CK under the Credential Access and Collection tactics in the Enterprise matrix, as a sub-technique of [T1557 Adversary-in-the-Middle](https://intel.threadlinqs.com/technique/T1557). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 7 high, 1 medium.

Threats that use T1557.001 most often also use [T1187 Forced Authentication](https://intel.threadlinqs.com/technique/T1187) (9 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (8 threats), [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (7 threats), [T1078.002 Domain Accounts](https://intel.threadlinqs.com/technique/T1078.002) (7 threats), [T1021.002 SMB/Windows Admin Shares](https://intel.threadlinqs.com/technique/T1021.002) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1557.001; the most frequent are [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1557.001.

- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1557.001, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content, Network Traffic Flow
- Service — Service Creation
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1

## Tracked threats

13 tracked threats use T1557.001.

- ["Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay](https://intel.threadlinqs.com/threat/TL-2026-2276) — high — 2026-09-01
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedures](https://intel.threadlinqs.com/threat/TL-2026-1966) — high — 2026-08-10
- [CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation](https://intel.threadlinqs.com/threat/TL-2026-1675) — critical — 2026-07-24
- [Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk…](https://intel.threadlinqs.com/threat/TL-2026-1638) — critical — 2026-07-22
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…](https://intel.threadlinqs.com/threat/TL-2026-1332) — high — 2026-07-14
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [Unpatched Windows search: URI Handler NTLMv2 Hash Leak via crumb=location UNC Coercion (No CVE, Microsoft…](https://intel.threadlinqs.com/threat/TL-2026-0673) — high — 2026-06-03
- [Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…](https://intel.threadlinqs.com/threat/TL-2026-0596) — high — 2026-05-26
- [CVE-2026-32202 — Windows Shell Protection Mechanism Failure: NTLM Authentication Coercion via Auto-Parsed…](https://intel.threadlinqs.com/threat/TL-2026-0435) — critical — 2026-04-29
- [AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55…](https://intel.threadlinqs.com/threat/TL-2026-0131) — critical — 2026-02-22
- [Microsoft NTLM Deprecation - Three-Stage Phase-Out Plan](https://intel.threadlinqs.com/threat/TL-2026-0040) — high — 2026-02-03
- [Microsoft NTLM Phase-Out: Detection & Migration Guidance](https://intel.threadlinqs.com/threat/TL-2026-0009) — medium — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T1557.001, most frequent first.

- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-54121](https://intel.threadlinqs.com/cve/CVE-2026-54121)
- [CVE-2026-60167](https://intel.threadlinqs.com/cve/CVE-2026-60167)
- [CVE-2026-60168](https://intel.threadlinqs.com/cve/CVE-2026-60168)
- [CVE-2026-60169](https://intel.threadlinqs.com/cve/CVE-2026-60169)
- [CVE-2026-60170](https://intel.threadlinqs.com/cve/CVE-2026-60170)

## Detection coverage

Threadlinqs maintains 55 detection rules mapped to T1557.001 (SPL 19, KQL 19, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

55 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1557 Adversary-in-the-Middle](https://intel.threadlinqs.com/technique/T1557) — 170 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1557.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
