T1550.003 - Pass the Ticket - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
November 4, 2025
Last Seen
July 3, 2026

T1550.003 - Pass the Ticket is a mitre_attack tracked across 8 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 3, 2026.

Related Threat Clusters

  • OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks

    From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…

    17 articles · Updated June 11, 2026
  • LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP

    On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…

    53 articles · Updated March 24, 2026
  • Salesloft Drift OAuth Token Breach Exposes Salesforce Data

    Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…

    3 articles · Updated June 21, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1553 articles · Updated February 12, 2026
  • ShinyHunters Claims Major Woflow Data Breach Affecting Multiple Clients

    ShinyHunters, a data extortion group, has claimed responsibility for a breach of Woflow, a software provider for merchant data used by companies like Uber, DoorDash, and Walmart. The group alleges that it stole several…

    2 articles · Updated March 6, 2026
  • Password Resets Fail to Mitigate Active Directory Breaches

    Changing passwords is a common response to suspected breaches in Active Directory (AD) environments, but it does not always eliminate the threat. Attackers can exploit cached password hashes, which may remain valid even…

    2 articles · Updated May 11, 2026
  • Curly COMrades Exploit Hyper-V for Covert Malware Operations

    The Russian hacker group Curly COMrades is exploiting Microsoft Hyper-V on compromised Windows machines to create hidden Alpine Linux-based virtual machines. These virtual environments allow the group to bypass endpoint…

    4 articles · Updated November 5, 2025
  • Curly COMrades Exploit Hyper-V for Covert Malware Operations

    The Russian hacker group Curly COMrades is utilizing Microsoft Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows systems, allowing them to bypass endpoint detection and maintain…

    5 articles · Updated November 5, 2025

Recent Intelligence Reports

  • An AI Agent Just Pulled Off a Full Ransomware Attack—and It Didn't Save the Decryption Key — Finance.Biggo · July 3, 2026
  • Data Theft Salesforce Instances Via Salesloft Drift — cloud.google.com · June 21, 2026
  • G0050 — attack.mitre.org · June 11, 2026
  • Why Changing Passwords Doesn't End an Active Directory Breach — Bleepingcomputer · May 11, 2026
  • LiteLLM loses game of Trivy pursuit, gets compromised — Theregister · March 24, 2026
  • ShinyHunters claims Woflow breach in supply chain hack — Securitybrief.Asia · March 6, 2026
  • Russian hackers abuse Hyper — Bleepingcomputer · November 4, 2025

CVSS v3.1 Breakdown