T1550.002 - Pass The Hash - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
April 23, 2026
Last Seen
September 9, 2026

Related Threat Clusters

  • AI-Driven Exploitation of PaperCut Vulnerabilities Compromises 440 Servers Globally

    A Russian-speaking threat actor has launched a global campaign utilizing artificial intelligence to exploit critical vulnerabilities in PaperCut NG/MF software, compromising at least 440 servers across 395 organizations…

    2 articles · Updated September 9, 2026
  • OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks

    From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…

    17 articles · Updated June 11, 2026
  • Urgent Threat from NTLMv1 Exploitation via Rainbow Tables

    In 2026, Mandiant released 8.6 terabytes of NTLMv1 rainbow tables, making it feasible to crack NTLMv1 hashes from Domain Controllers using consumer hardware. Attackers can now convert captured NTLMv1 hashes to NT hashes…

    2 articles · Updated September 8, 2026
  • Microsoft Teams Exploited for Helpdesk Impersonation Attacks

    Cyber attackers are increasingly using Microsoft Teams to impersonate IT helpdesk staff, employing social engineering tactics to gain remote access to enterprise systems. This method, known as 'cross-tenant helpdesk…

    51 articles · Updated April 20, 2026
  • Holm Security Launches Active Directory Security Amid Regulatory Pressure

    Holm Security has introduced Active Directory Security, enhancing its platform to continuously assess on-premises Active Directory for vulnerabilities. This launch coincides with increasing regulatory demands in Europe,…

    2 articles · Updated June 9, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1922 articles · Updated February 12, 2026
  • Password Resets Fail to Mitigate Active Directory Breaches

    Changing passwords is a common response to suspected breaches in Active Directory (AD) environments, but it does not always eliminate the threat. Attackers can exploit cached password hashes, which may remain valid even…

    2 articles · Updated May 11, 2026

Recent Intelligence Reports

  • Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF — Greynoise · September 9, 2026
  • NTLMv1 DC Rainbow Tables: Domain Compromise — adscanpro.com · September 8, 2026
  • Six Agencies Warn Gunra Ransomware Hacked MFA at Server Level; Linux Victims May ... — Techtimes · August 11, 2026
  • G0050 — attack.mitre.org · June 11, 2026
  • Holm Security expands platform with Active Directory Security to harden the most — Uk.Finance.Yahoo · June 9, 2026
  • Why Changing Passwords Doesn't End an Active Directory Breach — Bleepingcomputer · May 11, 2026
  • Why Changing Passwords Doesn’t End an Active Directory Breach — Bleepingcomputer · May 11, 2026
  • Hackers impersonate Microsoft Teams staff to deploy SNOW malware — Notebookcheck · April 24, 2026

CVSS v3.1 Breakdown