T1528Steal Application Access Token
T1528 — Steal Application Access Token is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 50 detection use cases covering it and 90 threat-intel articles citing it.
Credential Access
50Use cases
90Articles
0Sub-techniques
1Tactic
Use cases covering this technique (50)
OAuth consent / suspicious app grant [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Azure AD Device Code Authentication Azure AD OAuth Application Consent Granted By User Azure AD User Consent Blocked for Risky Application Azure AD User Consent Denied for OAuth Application O365 File Permissioned Application Consent Granted by User O365 Mail Permissioned Application Consent Granted by User O365 User Consent Blocked for Risky Application O365 User Consent Denied for OAuth Application [LLM] OWAReaper OAuth token theft via OWA service.svc GetClientAccessToken (IIS) [LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container [LLM] Suspicious OAuth application consent granting broad scopes (ShinyHunters DataLoader-style persistence) [LLM] Spike of AADSTS50011 redirect_uri mismatch at IdP (poisoned Poweradmin callback) [LLM] Victim account takeover: new-IP sign-in within 1h of redirect_uri mismatch (CVE-2026-54588) [LLM] ARToken/EvilTokens device-code phishing: contact with pamconj C2 and Cloudflare Workers lures [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) [LLM] TSDProxy x-tsdproxy-auth-token leaked to backend in upstream HTTP requests [LLM] Authorizer /authorize implicit-flow token leak to off-origin redirect_uri (CVE-2026-54072) [LLM] Authorizer /authorize redirect_uri iteration — multiple distinct targets from one source [LLM] Spike in Authorizer /authorize 302 redirects to off-origin hosts (bulk token exfiltration) [LLM] Nuclio cron pod shell reads Kubernetes service-account token (CVE-2026-52831 credential theft) [LLM] Better Auth OAuth refresh_token grant replayed without client_secret (CVE-2026-53512) [LLM] 9router API-key leak via unauthenticated GET /api/usage/stats and /api/usage/request-logs [LLM] Entra ID Device Authorization Grant (device code) authentication flow sign-in [LLM] Post-device-code token abuse: mailbox / OneDrive / Teams access from a new IP after device-code sign-in [LLM] 9router API key / secret exfiltration via /api/settings/database without prior login [LLM] Entra ID device registration = ARToken PRT persistence after device-code token theft [LLM] GitHub dead-drop C2 — commit-search for RevokeAndItGoesKaboom / TheBeautifulSandsOfTime [LLM] Salesforce API access bearing python-requests/aiohttp automation user-agent (Icarus OAuth abuse) [LLM] Salesforce connected-app OAuth access from first-seen ISP / anonymizing proxy (stolen-token reuse) [LLM] Malicious JetBrains Marketplace plugin install (15 DeepSeek/CodeGPT clone IDs) [LLM] Microsoft 365 OAuth device code authentication flow sign-in (EvilTokens) [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) [LLM] Cloud credential file access by node/python runtime [LLM] s1ngularity Nx compromise: telemetry.js postinstall harvesting tokens via gh auth token [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) [LLM] Package-manager process harvesting cloud metadata / Vault (IMDS 169.254.169.254, ECS 169.254.170.2, Vault :8200) [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) [LLM] Python process contacting AWS IMDS 169.254.169.254 (litellm stealer IAM credential theft) [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx [LLM] Reuse of CircleCI-exfiltrated secrets / stolen SSO session from breach attacker IPsArticles citing this technique (90)
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-114
crit Begun, the Patch Wars have art-150
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-246
high Catan and Mouse art-261
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-380
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
high Snyk Apps now GA: An easy, standardized, and secure framework for building custom integrations art-1488
crit API Security Guide art-1751