# T1606 Forge Web Credentials

> As of 2026-10-05, T1606 (Forge Web Credentials) appears in 93 tracked threats, first reported 2026-01-27 and most recently 2026-10-02, with linked actors including Scattered LAPSUS$ Hunters, Scattered Spider, ShinyHunters; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 93 (54 critical, 36 high, 3 medium)
- **First seen:** 2026-01-27
- **Last seen:** 2026-10-02
- **Threat actors:** 28
- **Detection rules:** 74 (counts only; Blue tier and above)

## Key facts

- **ID:** T1606
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1606/

## Activity timeline

T1606 first appeared in tracked threats on 2026-01-27 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 44 reports, and 93 of the 93 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1606 Forge Web Credentials is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 93 of 2623 tracked threats (3.5%) to it; by severity that is 54 critical, 36 high, 3 medium.

Threats that use T1606 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (69 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (64 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (43 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (43 threats), [T1213 Data from Information Repositories](https://intel.threadlinqs.com/technique/T1213) (41 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

28 tracked threat actors appear in the threats that use T1606; the most frequent are [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (4), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (4), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (4), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (4), [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) (4).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1606.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1606, per MITRE ATT&CK.

- Logon Session — Logon Session Creation
- Web Credential — Web Credential Creation, Web Credential Usage

## Threat actors using it

- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 4
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 4
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 4
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 4
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 4
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 4
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 4
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 3
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 3
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 3

## Tracked threats

The 30 most recent of 93 tracked threats that use T1606.

- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…](https://intel.threadlinqs.com/threat/TL-2026-2851) — critical — 2026-10-02
- [Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rows](https://intel.threadlinqs.com/threat/TL-2026-2675) — high — 2026-09-26
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-2680) — critical — 2026-09-25
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After Disclosure](https://intel.threadlinqs.com/threat/TL-2026-2287) — critical — 2026-09-01
- [AI-Accelerated WordPress Plugin Vulnerability Research Surfaces 16 Unreported Bugs Across Dozens of Plugins](https://intel.threadlinqs.com/threat/TL-2026-2021) — high — 2026-08-15
- [China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes, OpenClaw) to Breach Taiwan Government and…](https://intel.threadlinqs.com/threat/TL-2026-1997) — critical — 2026-08-12
- [Metabase Zero-Day (GHSA-vwf4-m7j8-wcjf): Unauthenticated SQL Injection via /api/session/reset_password…](https://intel.threadlinqs.com/threat/TL-2026-1969) — critical — 2026-08-10
- [Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra ID](https://intel.threadlinqs.com/threat/TL-2026-1952) — high — 2026-08-09
- [Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)](https://intel.threadlinqs.com/threat/TL-2026-1898) — critical — 2026-08-05
- [Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials…](https://intel.threadlinqs.com/threat/TL-2026-1888) — high — 2026-08-05
- [Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)](https://intel.threadlinqs.com/threat/TL-2026-1886) — high — 2026-08-05
- [Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)](https://intel.threadlinqs.com/threat/TL-2026-1861) — critical — 2026-08-04
- [Google Password Manager — Three Post-Compromise Attack Paths Against Chrome Cloud Authenticator (Pass-ta-key…](https://intel.threadlinqs.com/threat/TL-2026-1843) — high — 2026-08-03
- [CVE-2026-28323: SolarWinds Web Help Desk SAML Authentication Bypass](https://intel.threadlinqs.com/threat/TL-2026-1789) — critical — 2026-07-31
- [CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-1755) — critical — 2026-07-29
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1650) — critical — 2026-07-23
- [CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine…](https://intel.threadlinqs.com/threat/TL-2026-1627) — critical — 2026-07-22
- [Vibe-Coded Applications Riddled With Exploitable Security Flaws — Theori Xint.io Study Finds 434 Issues…](https://intel.threadlinqs.com/threat/TL-2026-1622) — medium — 2026-07-22
- [German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit…](https://intel.threadlinqs.com/threat/TL-2026-1612) — high — 2026-07-22
- [German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM…](https://intel.threadlinqs.com/threat/TL-2026-1602) — high — 2026-07-22
- [CVE-2026-52824: Kimai Docker Image Hardcoded APP_SECRET Enables Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1556) — high — 2026-07-20
- [Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft…](https://intel.threadlinqs.com/threat/TL-2026-1497) — high — 2026-07-18
- [CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-1460) — critical — 2026-07-17
- [CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token Exchange](https://intel.threadlinqs.com/threat/TL-2026-1436) — high — 2026-07-17
- [CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-1434) — critical — 2026-07-17
- [Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164…](https://intel.threadlinqs.com/threat/TL-2026-1430) — high — 2026-07-17
- [Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and…](https://intel.threadlinqs.com/threat/TL-2026-1388) — high — 2026-07-15
- [CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659…](https://intel.threadlinqs.com/threat/TL-2026-1378) — critical — 2026-07-15

## Related CVEs

CVEs referenced by the tracked threats that use T1606, most frequent first.

- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-40372](https://intel.threadlinqs.com/cve/CVE-2026-40372)
- [CVE-2026-48558](https://intel.threadlinqs.com/cve/CVE-2026-48558)
- [CVE-2026-8451](https://intel.threadlinqs.com/cve/CVE-2026-8451)
- [CVE-2021-39935](https://intel.threadlinqs.com/cve/CVE-2021-39935)
- [CVE-2022-26923](https://intel.threadlinqs.com/cve/CVE-2022-26923)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2025-12101](https://intel.threadlinqs.com/cve/CVE-2025-12101)
- [CVE-2025-34291](https://intel.threadlinqs.com/cve/CVE-2025-34291)
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-62554](https://intel.threadlinqs.com/cve/CVE-2025-62554)
- [CVE-2025-62557](https://intel.threadlinqs.com/cve/CVE-2025-62557)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10816](https://intel.threadlinqs.com/cve/CVE-2026-10816)
- [CVE-2026-10817](https://intel.threadlinqs.com/cve/CVE-2026-10817)
- [CVE-2026-11374](https://intel.threadlinqs.com/cve/CVE-2026-11374)
- [CVE-2026-13474](https://intel.threadlinqs.com/cve/CVE-2026-13474)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)

## Detection coverage

Threadlinqs maintains 74 detection rules mapped to T1606 (SPL 31, KQL 23, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.

74 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1606.001 Web Cookies — 9 tracked threats
- T1606.002 SAML Tokens — 9 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1606
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
