Activity timeline
T1087.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 15 reports, and 45 of the 45 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1087.004 Cloud Account is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of T1087 Account Discovery. Threadlinqs maps 45 of 2623 tracked threats (1.7%) to it; by severity that is 7 critical, 34 high, 3 medium, 1 low.
Threats that use T1087.004 most often also use T1078.004 Cloud Accounts (37 threats), T1550.001 Application Access Token (29 threats), T1528 Steal Application Access Token (28 threats), T1526 Cloud Service Discovery (23 threats), T1114.002 Remote Email Collection (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
22 tracked threat actors appear in the threats that use T1087.004; the most frequent are ShinyHunters (3), EvilTokens (2), Greatness PhaaS Operators (2), Kali365 PhaaS operators (2), Storm-2755 (2).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1087.004.
Data sources
Telemetry that can reveal T1087.004, per MITRE ATT&CK.
- Command — Command Execution
Threat actors using it
Tracked threats
The 30 most recent of 45 tracked threats that use T1087.004.
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…high
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)high
- TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…high
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chainhigh
- OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…high
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Coordinated GitHub API Enumeration and Access Token Abuse Campaignhigh
- Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…medium
- CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…critical
- Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCShigh
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…high
- OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio…high
- Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)medium
- AWS IAM Privilege Escalation Attack Path via iam:CreateAccessKey, iam:UpdateLoginProfile, and…medium
- Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromisehigh
- Metabase Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited in the Wild for Unauthenticated Admin Accesscritical
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidentshigh
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…high
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokenshigh
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…high
- Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraudlow
- CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligencehigh
- CosmosEscape: Azure Cosmos DB Gremlin Sandbox Escape Exposed Platform-Wide Master Key (CVE-2026-66803)critical
- Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accountshigh
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…high
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Accesshigh
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths…high
Detection coverage
Threadlinqs maintains 87 detection rules mapped to T1087.004 (SPL 30, KQL 33, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1087 Account Discovery — 339 tracked threats at the technique level.