# T1657 Financial Theft

> As of 2026-10-05, T1657 (Financial Theft) appears in 468 tracked threats, first reported 2021-11-25 and most recently 2026-10-04, with linked actors including ShinyHunters, APT38, Lazarus Group; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 468 (82 critical, 297 high, 80 medium, 5 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-04
- **Threat actors:** 114
- **Detection rules:** 552 (counts only; Blue tier and above)

## Key facts

- **ID:** T1657
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1657/

## Activity timeline

T1657 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 163 reports, and 467 of the 468 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1657 Financial Theft is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 468 of 2623 tracked threats (17.8%) to it; by severity that is 82 critical, 297 high, 80 medium, 5 low.

Threats that use T1657 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (216 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (204 threats), [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (187 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (183 threats), [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (179 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

114 tracked threat actors appear in the threats that use T1657; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (22), [APT38](https://intel.threadlinqs.com/actor/APT38) (15), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (13), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (11), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (11).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1657.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)

## Data sources

Telemetry that can reveal T1657, per MITRE ATT&CK.

- Application Log — Application Log Content

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 22
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 15
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 13
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 11
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 11
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 10
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 9
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 9
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 9
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 8
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 8
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 8

## Tracked threats

The 30 most recent of 468 tracked threats that use T1657.

- [Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…](https://intel.threadlinqs.com/threat/TL-2026-2919) — high — 2026-10-04
- [Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty](https://intel.threadlinqs.com/threat/TL-2026-2908) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board…](https://intel.threadlinqs.com/threat/TL-2026-2898) — high — 2026-10-04
- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2873) — high — 2026-10-03
- [City of Vicksburg, Mississippi shuts down systems after ransomware attack](https://intel.threadlinqs.com/threat/TL-2026-2862) — medium — 2026-10-02
- [Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…](https://intel.threadlinqs.com/threat/TL-2026-2839) — high — 2026-10-02
- [Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach](https://intel.threadlinqs.com/threat/TL-2026-2842) — medium — 2026-10-01
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA](https://intel.threadlinqs.com/threat/TL-2026-2834) — high — 2026-10-01
- [Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group](https://intel.threadlinqs.com/threat/TL-2026-2829) — high — 2026-10-01
- [Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)](https://intel.threadlinqs.com/threat/TL-2026-2823) — critical — 2026-10-01
- [Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles](https://intel.threadlinqs.com/threat/TL-2026-2799) — medium — 2026-09-30
- [Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+…](https://intel.threadlinqs.com/threat/TL-2026-2792) — medium — 2026-09-29
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [Fake American Express "non-compliance" card-lock phishing campaign targets Australians](https://intel.threadlinqs.com/threat/TL-2026-2758) — medium — 2026-09-29
- [Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)](https://intel.threadlinqs.com/threat/TL-2026-2757) — high — 2026-09-28
- [TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace](https://intel.threadlinqs.com/threat/TL-2026-2715) — medium — 2026-09-27
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2707) — medium — 2026-09-27
- [ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer](https://intel.threadlinqs.com/threat/TL-2026-2699) — high — 2026-09-27
- [Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible…](https://intel.threadlinqs.com/threat/TL-2026-2690) — critical — 2026-09-27
- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…](https://intel.threadlinqs.com/threat/TL-2026-2673) — high — 2026-09-26
- [ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Site](https://intel.threadlinqs.com/threat/TL-2026-2671) — critical — 2026-09-26
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via…](https://intel.threadlinqs.com/threat/TL-2026-2656) — high — 2026-09-26
- [Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)](https://intel.threadlinqs.com/threat/TL-2026-2713) — medium — 2026-09-25
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — medium — 2026-09-25
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25

## Related CVEs

CVEs referenced by the tracked threats that use T1657, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2023-43000](https://intel.threadlinqs.com/cve/CVE-2023-43000)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-64328](https://intel.threadlinqs.com/cve/CVE-2025-64328)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2019-19006](https://intel.threadlinqs.com/cve/CVE-2019-19006)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)

## Detection coverage

Threadlinqs maintains 552 detection rules mapped to T1657 (SPL 165, KQL 184, Sigma 203). Rule content is available to Blue tier accounts and above; this page shows counts only.

552 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1657
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
