# T1649 Steal or Forge Authentication Certificates

> As of 2026-10-05, T1649 (Steal or Forge Authentication Certificates) appears in 33 tracked threats, first reported 2026-02-02 and most recently 2026-09-27, with linked actors including NightmareEclipse, APT28, APT43; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 33 (13 critical, 16 high, 4 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-27
- **Threat actors:** 9
- **Detection rules:** 43 (counts only; Blue tier and above)

## Key facts

- **ID:** T1649
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1649/

## Activity timeline

T1649 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 11 reports, and 33 of the 33 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1649 Steal or Forge Authentication Certificates is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 33 of 2623 tracked threats (1.3%) to it; by severity that is 13 critical, 16 high, 4 medium.

Threats that use T1649 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (20 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (17 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (16 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (16 threats), [T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003) (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1649; the most frequent are [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (1), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1649.

- [M1015 Active Directory Configuration](https://attack.mitre.org/mitigations/M1015/)
- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1649, per MITRE ATT&CK.

- Active Directory — Active Directory Credential Request, Active Directory Object Modification
- Application Log — Application Log Content
- Command — Command Execution
- File — File Access
- Logon Session — Logon Session Creation
- Windows Registry — Windows Registry Key Access

## Threat actors using it

- [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Interlock](https://intel.threadlinqs.com/actor/Interlock) — 1
- [Interlock Ransomware Group](https://intel.threadlinqs.com/actor/Interlock%20Ransomware%20Group) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 1

## Tracked threats

The 30 most recent of 33 tracked threats that use T1649.

- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30
- [ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodology](https://intel.threadlinqs.com/threat/TL-2026-2168) — high — 2026-08-27
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targeting](https://intel.threadlinqs.com/threat/TL-2026-2104) — high — 2026-08-21
- [Google Password Manager — Three Post-Compromise Attack Paths Against Chrome Cloud Authenticator (Pass-ta-key…](https://intel.threadlinqs.com/threat/TL-2026-1843) — high — 2026-08-03
- [Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…](https://intel.threadlinqs.com/threat/TL-2026-1766) — critical — 2026-07-30
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation](https://intel.threadlinqs.com/threat/TL-2026-1675) — critical — 2026-07-24
- [LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…](https://intel.threadlinqs.com/threat/TL-2026-1449) — high — 2026-07-17
- [LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public…](https://intel.threadlinqs.com/threat/TL-2026-1445) — high — 2026-07-17
- [July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days](https://intel.threadlinqs.com/threat/TL-2026-1437) — critical — 2026-07-17
- [Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-1350) — critical — 2026-07-15
- [CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-1349) — high — 2026-07-15
- [CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day](https://intel.threadlinqs.com/threat/TL-2026-1346) — medium — 2026-07-15
- [CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public)](https://intel.threadlinqs.com/threat/TL-2026-1341) — critical — 2026-07-14
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote…](https://intel.threadlinqs.com/threat/TL-2026-0626) — high — 2026-05-29
- [Fortinet Critical Unauthenticated RCE — FortiAuthenticator CVE-2026-44277 & FortiSandbox CVE-2026-26083](https://intel.threadlinqs.com/threat/TL-2026-0503) — critical — 2026-05-12
- [Unit 42 Deep Dive: Advanced AD CS Exploitation — Certificate Template Misuse (ESC1) and Shadow Credentials…](https://intel.threadlinqs.com/threat/TL-2026-0497) — high — 2026-05-11
- [Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973…](https://intel.threadlinqs.com/threat/TL-2026-0477) — high — 2026-05-07
- [Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…](https://intel.threadlinqs.com/threat/TL-2026-0456) — high — 2026-05-04
- [cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-0440) — critical — 2026-04-30
- [PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation…](https://intel.threadlinqs.com/threat/TL-2026-0420) — high — 2026-04-24
- [Cisco Secure Firewall Management Center Insecure Java Deserialization RCE (CVE-2026-20131) — Interlock…](https://intel.threadlinqs.com/threat/TL-2026-0260) — critical — 2026-03-21
- [UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware…](https://intel.threadlinqs.com/threat/TL-2026-0221) — critical — 2026-03-13
- [25 Zero-Knowledge Bypass Vulnerabilities in Cloud Password Managers (Bitwarden/LastPass/Dashlane) — ETH…](https://intel.threadlinqs.com/threat/TL-2026-0122) — high — 2026-02-17
- [TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37…](https://intel.threadlinqs.com/threat/TL-2026-0109) — critical — 2026-02-06
- [White House Revokes Biden-Era Software Security Memorandums](https://intel.threadlinqs.com/threat/TL-2026-0048) — medium — 2026-02-03

## Related CVEs

CVEs referenced by the tracked threats that use T1649, most frequent first.

- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2022-22948](https://intel.threadlinqs.com/cve/CVE-2022-22948)
- [CVE-2022-26923](https://intel.threadlinqs.com/cve/CVE-2022-26923)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20867](https://intel.threadlinqs.com/cve/CVE-2023-20867)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-34048](https://intel.threadlinqs.com/cve/CVE-2023-34048)
- [CVE-2024-3094](https://intel.threadlinqs.com/cve/CVE-2024-3094)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-21590](https://intel.threadlinqs.com/cve/CVE-2025-21590)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2026-26083](https://intel.threadlinqs.com/cve/CVE-2026-26083)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)

## Detection coverage

Threadlinqs maintains 43 detection rules mapped to T1649 (SPL 16, KQL 12, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.

43 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1649
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
