Activity timeline
T1606 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 44 reports, and 93 of the 93 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1606 Forge Web Credentials is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 93 of 2623 tracked threats (3.5%) to it; by severity that is 54 critical, 36 high, 3 medium.
Threats that use T1606 most often also use T1190 Exploit Public-Facing Application (69 threats), T1078 Valid Accounts (64 threats), T1005 Data from Local System (43 threats), T1068 Exploitation for Privilege Escalation (43 threats), T1213 Data from Information Repositories (41 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
28 tracked threat actors appear in the threats that use T1606; the most frequent are Scattered LAPSUS$ Hunters (4), Scattered Spider (4), ShinyHunters (4), The Com (4), UNC5537 (4).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1606.
Data sources
Telemetry that can reveal T1606, per MITRE ATT&CK.
- Logon Session — Logon Session Creation
- Web Credential — Web Credential Creation, Web Credential Usage
Threat actors using it
Tracked threats
The 30 most recent of 93 tracked threats that use T1606.
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…critical
- Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rowshigh
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…critical
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After Disclosurecritical
- AI-Accelerated WordPress Plugin Vulnerability Research Surfaces 16 Unreported Bugs Across Dozens of Pluginshigh
- China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes, OpenClaw) to Breach Taiwan Government and…critical
- Metabase Zero-Day (GHSA-vwf4-m7j8-wcjf): Unauthenticated SQL Injection via /api/session/reset_password…critical
- Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra IDhigh
- Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)critical
- Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials…high
- Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)high
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)critical
- Google Password Manager — Three Post-Compromise Attack Paths Against Chrome Cloud Authenticator (Pass-ta-key…high
- CVE-2026-28323: SolarWinds Web Help Desk SAML Authentication Bypasscritical
- CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…critical
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEVcritical
- CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine…critical
- Vibe-Coded Applications Riddled With Exploitable Security Flaws — Theori Xint.io Study Finds 434 Issues…medium
- German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit…high
- German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM…high
- CVE-2026-52824: Kimai Docker Image Hardcoded APP_SECRET Enables Account Takeoverhigh
- Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft…high
- CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Exploited in the Wildcritical
- CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token Exchangehigh
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalogcritical
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164…high
- Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and…high
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659…critical
Detection coverage
Threadlinqs maintains 74 detection rules mapped to T1606 (SPL 31, KQL 23, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1606.001 Web Cookies — 9 tracked threats
- T1606.002 SAML Tokens — 9 tracked threats