T1098.001Additional Cloud Credentials
T1098.001 — Additional Cloud Credentials is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 7 detection use cases covering it and 55 threat-intel articles citing it.
PersistencePrivilege Escalation
7Use cases
55Articles
0Sub-techniques
2Tactics
↑ Parent technique: T1098 · Account Manipulation
Use cases covering this technique (7)
OAuth consent / suspicious app grant [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Azure AD Service Principal New Client Credentials O365 Service Principal New Client Credentials [LLM] AI resource key creation paired with logging/alert teardown in cloud control plane [LLM] High-privilege OAuth consent grant to Flowise application (offline_access / Mail / Files)Articles citing this technique (55)
crit Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS art-101
crit Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials art-193
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-221
crit Begun, the Patch Wars have art-253
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-426
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-469
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-515
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-520
high Snyk Apps now GA: An easy, standardized, and secure framework for building custom integrations art-1511
crit API Security Guide art-1774