Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1528

T1528Steal Application Access Token

T1528 — Steal Application Access Token is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 50 detection use cases covering it and 71 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
50Use cases
71Articles
0Sub-techniques
1Tactic

Use cases covering this technique (50)

OAuth consent / suspicious app grant Internal actions · alerting DSΣP [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Azure AD Device Code Authentication ESCU actions · alerting P Azure AD OAuth Application Consent Granted By User ESCU actions · alerting P Azure AD User Consent Blocked for Risky Application ESCU actions · alerting P Azure AD User Consent Denied for OAuth Application ESCU actions · alerting P O365 File Permissioned Application Consent Granted by User ESCU actions · alerting P O365 Mail Permissioned Application Consent Granted by User ESCU actions · alerting P O365 User Consent Blocked for Risky Application ESCU actions · alerting P O365 User Consent Denied for OAuth Application ESCU actions · alerting P [LLM] new-api CVE-2026-64859: admin user-list/detail API access token disclosure scoping Bespoke exploit · hunting SΣP [LLM] new-api CVE-2026-64859: root-only /api/option config change following user-record access from same IP Bespoke actions · alerting SP [LLM] Unauthenticated Flowise OAuth2 token-refresh endpoint access from external source (CVE-2026-70478) Bespoke exploit · alerting SΣP [LLM] Flowise mass OAuth token harvest — burst of successful refreshes across credentials Bespoke actions · alerting SP [LLM] High-privilege OAuth consent grant to Flowise application (offline_access / Mail / Files) Bespoke install · hunting DSΣDD [LLM] Bun runtime executing Shai-Hulud Math_Symbol.js credential stealer Bespoke actions · alerting DSΣPDDCS [LLM] npm-install child process reading developer credential stores (keyv stealer) Bespoke actions · hunting DSΣPDDCS [LLM] Entra ID sign-in or session from Storm-2945 AiTM device-code phishing infrastructure Bespoke actions · hunting DSΣPDD [LLM] vault-secrets-webhook mints SA tokens via TokenRequest after admission (CVE-2026-54725) Bespoke actions · alerting SPDD [LLM] Successful Entra ID device-code authentication (ARToken/EvilTokens PhaaS MFA bypass) Bespoke delivery · hunting DSΣP [LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container Bespoke recon · hunting DSΣPDDCS [LLM] Spike of AADSTS50011 redirect_uri mismatch at IdP (poisoned Poweradmin callback) Bespoke exploit · alerting DSPDD [LLM] Victim account takeover: new-IP sign-in within 1h of redirect_uri mismatch (CVE-2026-54588) Bespoke actions · alerting DSP [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) Bespoke actions · alerting SΣPDD [LLM] TSDProxy x-tsdproxy-auth-token leaked to backend in upstream HTTP requests Bespoke exploit · hunting SPDD [LLM] Authorizer /authorize implicit-flow token leak to off-origin redirect_uri (CVE-2026-54072) Bespoke exploit · alerting SΣP [LLM] Authorizer /authorize redirect_uri iteration — multiple distinct targets from one source Bespoke exploit · alerting SP [LLM] Spike in Authorizer /authorize 302 redirects to off-origin hosts (bulk token exfiltration) Bespoke actions · hunting SP [LLM] GitHub dead-drop C2 — commit-search for RevokeAndItGoesKaboom / TheBeautifulSandsOfTime Bespoke c2 · hunting DSPCS [LLM] Salesforce API access bearing python-requests/aiohttp automation user-agent (Icarus OAuth abuse) Bespoke actions · alerting DSP [LLM] Salesforce connected-app OAuth access from first-seen ISP / anonymizing proxy (stolen-token reuse) Bespoke exploit · hunting DSP [LLM] Malicious JetBrains Marketplace plugin install (15 DeepSeek/CodeGPT clone IDs) Bespoke install · hunting DSΣPDDCS [LLM] Microsoft 365 OAuth device code authentication flow sign-in (EvilTokens) Bespoke exploit · hunting DSΣPDD [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) Bespoke delivery · hunting DSΣPDD [LLM] Cloud credential file access by node/python runtime Bespoke actions · hunting DSΣPDDCS [LLM] s1ngularity Nx compromise: telemetry.js postinstall harvesting tokens via gh auth token Bespoke actions · alerting DSΣPDDCS [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) Bespoke actions · alerting DSPDDCS [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Package-manager process harvesting cloud metadata / Vault (IMDS 169.254.169.254, ECS 169.254.170.2, Vault :8200) Bespoke actions · hunting DSPDDCS [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) Bespoke actions · hunting DSPDDCS [LLM] Python process contacting AWS IMDS 169.254.169.254 (litellm stealer IAM credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) Bespoke actions · alerting DSΣPDDCS [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx Bespoke actions · alerting DSΣPDDCS [LLM] Reuse of CircleCI-exfiltrated secrets / stolen SSO session from breach attacker IPs Bespoke actions · hunting DSΣPDDCSCW

Articles citing this technique (71)