Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1528

T1528Steal Application Access Token

T1528 — Steal Application Access Token is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 50 detection use cases covering it and 90 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
50Use cases
90Articles
0Sub-techniques
1Tactic

Use cases covering this technique (50)

OAuth consent / suspicious app grant Internal actions · alerting DSΣP [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Azure AD Device Code Authentication ESCU actions · alerting P Azure AD OAuth Application Consent Granted By User ESCU actions · alerting P Azure AD User Consent Blocked for Risky Application ESCU actions · alerting P Azure AD User Consent Denied for OAuth Application ESCU actions · alerting P O365 File Permissioned Application Consent Granted by User ESCU actions · alerting P O365 Mail Permissioned Application Consent Granted by User ESCU actions · alerting P O365 User Consent Blocked for Risky Application ESCU actions · alerting P O365 User Consent Denied for OAuth Application ESCU actions · alerting P [LLM] OWAReaper OAuth token theft via OWA service.svc GetClientAccessToken (IIS) Bespoke actions · hunting SP [LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container Bespoke recon · hunting DSΣPDDCS [LLM] Suspicious OAuth application consent granting broad scopes (ShinyHunters DataLoader-style persistence) Bespoke c2 · hunting DSΣPDD [LLM] Spike of AADSTS50011 redirect_uri mismatch at IdP (poisoned Poweradmin callback) Bespoke exploit · alerting DSPDD [LLM] Victim account takeover: new-IP sign-in within 1h of redirect_uri mismatch (CVE-2026-54588) Bespoke actions · alerting DSP [LLM] ARToken/EvilTokens device-code phishing: contact with pamconj C2 and Cloudflare Workers lures Bespoke delivery · alerting DSΣPDDCS [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) Bespoke actions · alerting SΣPDD [LLM] TSDProxy x-tsdproxy-auth-token leaked to backend in upstream HTTP requests Bespoke exploit · hunting SPDD [LLM] Authorizer /authorize implicit-flow token leak to off-origin redirect_uri (CVE-2026-54072) Bespoke exploit · alerting SΣP [LLM] Authorizer /authorize redirect_uri iteration — multiple distinct targets from one source Bespoke exploit · alerting SP [LLM] Spike in Authorizer /authorize 302 redirects to off-origin hosts (bulk token exfiltration) Bespoke actions · hunting SP [LLM] Nuclio cron pod shell reads Kubernetes service-account token (CVE-2026-52831 credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Better Auth OAuth refresh_token grant replayed without client_secret (CVE-2026-53512) Bespoke exploit · alerting SP [LLM] 9router API-key leak via unauthenticated GET /api/usage/stats and /api/usage/request-logs Bespoke actions · alerting SΣP [LLM] Entra ID Device Authorization Grant (device code) authentication flow sign-in Bespoke exploit · alerting DSΣPDD [LLM] Post-device-code token abuse: mailbox / OneDrive / Teams access from a new IP after device-code sign-in Bespoke actions · alerting DS [LLM] 9router API key / secret exfiltration via /api/settings/database without prior login Bespoke actions · alerting SP [LLM] Entra ID device registration = ARToken PRT persistence after device-code token theft Bespoke install · hunting DSΣDD [LLM] GitHub dead-drop C2 — commit-search for RevokeAndItGoesKaboom / TheBeautifulSandsOfTime Bespoke c2 · hunting DSPCS [LLM] Salesforce API access bearing python-requests/aiohttp automation user-agent (Icarus OAuth abuse) Bespoke actions · alerting DSP [LLM] Salesforce connected-app OAuth access from first-seen ISP / anonymizing proxy (stolen-token reuse) Bespoke exploit · hunting DSP [LLM] Malicious JetBrains Marketplace plugin install (15 DeepSeek/CodeGPT clone IDs) Bespoke install · hunting DSΣPDDCS [LLM] Microsoft 365 OAuth device code authentication flow sign-in (EvilTokens) Bespoke exploit · hunting DSΣPDD [LLM] EvilTokens device-code token polling from attacker infra (python-requests UA / C2 IPs) Bespoke delivery · hunting DSΣPDD [LLM] Cloud credential file access by node/python runtime Bespoke actions · hunting DSΣPDDCS [LLM] s1ngularity Nx compromise: telemetry.js postinstall harvesting tokens via gh auth token Bespoke actions · alerting DSΣPDDCS [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) Bespoke actions · alerting DSPDDCS [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Package-manager process harvesting cloud metadata / Vault (IMDS 169.254.169.254, ECS 169.254.170.2, Vault :8200) Bespoke actions · hunting DSPDDCS [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) Bespoke actions · hunting DSPDDCS [LLM] Python process contacting AWS IMDS 169.254.169.254 (litellm stealer IAM credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) Bespoke actions · alerting DSΣPDDCS [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx Bespoke actions · alerting DSΣPDDCS [LLM] Reuse of CircleCI-exfiltrated secrets / stolen SSO session from breach attacker IPs Bespoke actions · hunting DSΣPDDCSCW

Articles citing this technique (90)