Activity timeline
T1649 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 11 reports, and 33 of the 33 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1649 Steal or Forge Authentication Certificates is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 33 of 2623 tracked threats (1.3%) to it; by severity that is 13 critical, 16 high, 4 medium.
Threats that use T1649 most often also use T1078 Valid Accounts (20 threats), T1068 Exploitation for Privilege Escalation (17 threats), T1005 Data from Local System (16 threats), T1190 Exploit Public-Facing Application (16 threats), T1003 OS Credential Dumping (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1649; the most frequent are NightmareEclipse (2), APT28 (1), APT43 (1), BlueDelta (1), Forest Blizzard (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1649.
Data sources
Telemetry that can reveal T1649, per MITRE ATT&CK.
- Active Directory — Active Directory Credential Request, Active Directory Object Modification
- Application Log — Application Log Content
- Command — Command Execution
- File — File Access
- Logon Session — Logon Session Creation
- Windows Registry — Windows Registry Key Access
Threat actors using it
Tracked threats
The 30 most recent of 33 tracked threats that use T1649.
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitationcritical
- Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…high
- ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodologyhigh
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victimshigh
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targetinghigh
- Google Password Manager — Three Post-Compromise Attack Paths Against Chrome Cloud Authenticator (Pass-ta-key…high
- Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…critical
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonationcritical
- LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…high
- LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public…high
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Dayscritical
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint…critical
- CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively Exploitedhigh
- CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Daymedium
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public)critical
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote…high
- Fortinet Critical Unauthenticated RCE — FortiAuthenticator CVE-2026-44277 & FortiSandbox CVE-2026-26083critical
- Unit 42 Deep Dive: Advanced AD CS Exploitation — Certificate Template Misuse (ESC1) and Shadow Credentials…high
- Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973…high
- Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…high
- cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEVcritical
- PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation…high
- Cisco Secure Firewall Management Center Insecure Java Deserialization RCE (CVE-2026-20131) — Interlock…critical
- UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware…critical
- 25 Zero-Knowledge Bypass Vulnerabilities in Cloud Password Managers (Bitwarden/LastPass/Dashlane) — ETH…high
- TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37…critical
- White House Revokes Biden-Era Software Security Memorandumsmedium
Detection coverage
Threadlinqs maintains 43 detection rules mapped to T1649 (SPL 16, KQL 12, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.