Activity timeline
T1657 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 163 reports, and 467 of the 468 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1657 Financial Theft is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 468 of 2623 tracked threats (17.8%) to it; by severity that is 82 critical, 297 high, 80 medium, 5 low.
Threats that use T1657 most often also use T1005 Data from Local System (216 threats), T1027 Obfuscated Files or Information (204 threats), T1583 Acquire Infrastructure (187 threats), T1567 Exfiltration Over Web Service (183 threats), T1566 Phishing (179 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
114 tracked threat actors appear in the threats that use T1657; the most frequent are ShinyHunters (22), APT38 (15), Lazarus Group (13), Andariel (11), Scattered Spider (11).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1657.
Data sources
Telemetry that can reveal T1657, per MITRE ATT&CK.
- Application Log — Application Log Content
Threat actors using it
Tracked threats
The 30 most recent of 468 tracked threats that use T1657.
- Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…high
- Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guiltyhigh
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board…high
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…high
- City of Vicksburg, Mississippi shuts down systems after ransomware attackmedium
- Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…high
- Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breachmedium
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFAhigh
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Grouphigh
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)critical
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Rolesmedium
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+…medium
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- Fake American Express "non-compliance" card-lock phishing campaign targets Australiansmedium
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)high
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplacemedium
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…medium
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealerhigh
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible…critical
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threatcritical
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…high
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Sitecritical
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via…high
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)medium
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Scriptmedium
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…high
Detection coverage
Threadlinqs maintains 552 detection rules mapped to T1657 (SPL 165, KQL 184, Sigma 203). Rule content is available to Blue tier accounts and above; this page shows counts only.