# T1087.004 Cloud Account

> As of 2026-10-05, T1087.004 (Cloud Account) appears in 45 tracked threats, first reported 2026-04-20 and most recently 2026-10-03, with linked actors including ShinyHunters, EvilTokens, Greatness PhaaS Operators; it most often appears alongside T1078.004 (Cloud Accounts).

- **Tracked threats:** 45 (7 critical, 34 high, 3 medium, 1 low)
- **First seen:** 2026-04-20
- **Last seen:** 2026-10-03
- **Threat actors:** 22
- **Detection rules:** 87 (counts only; Blue tier and above)

## Key facts

- **ID:** T1087.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Parent:** T1087
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1087/004/

## Activity timeline

T1087.004 first appeared in tracked threats on 2026-04-20 and was most recently reported on 2026-10-03. The busiest month was 2026-08 with 15 reports, and 45 of the 45 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1087.004 Cloud Account is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of [T1087 Account Discovery](https://intel.threadlinqs.com/technique/T1087). Threadlinqs maps 45 of 2623 tracked threats (1.7%) to it; by severity that is 7 critical, 34 high, 3 medium, 1 low.

Threats that use T1087.004 most often also use [T1078.004 Cloud Accounts](https://intel.threadlinqs.com/technique/T1078.004) (37 threats), [T1550.001 Application Access Token](https://intel.threadlinqs.com/technique/T1550.001) (29 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (28 threats), [T1526 Cloud Service Discovery](https://intel.threadlinqs.com/technique/T1526) (23 threats), [T1114.002 Remote Email Collection](https://intel.threadlinqs.com/technique/T1114.002) (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

22 tracked threat actors appear in the threats that use T1087.004; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (3), [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) (2), [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) (2), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (2), [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) (2).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1087.004.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1087.004, per MITRE ATT&CK.

- Command — Command Execution

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 3
- [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) — 2
- [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) — 2
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 2
- [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) — 2
- [Storm-2992](https://intel.threadlinqs.com/actor/Storm-2992) — 2
- [TheHatman](https://intel.threadlinqs.com/actor/TheHatman) — 2
- [UNK_OutFlareAZ](https://intel.threadlinqs.com/actor/UNK_OutFlareAZ) — 2
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Coinbase Cartel](https://intel.threadlinqs.com/actor/Coinbase%20Cartel) — 1
- [CoinbaseCartel](https://intel.threadlinqs.com/actor/CoinbaseCartel) — 1

## Tracked threats

The 30 most recent of 45 tracked threats that use T1087.004.

- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2873) — high — 2026-10-03
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)](https://intel.threadlinqs.com/threat/TL-2026-2628) — high — 2026-09-23
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain](https://intel.threadlinqs.com/threat/TL-2026-2601) — high — 2026-09-21
- [OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…](https://intel.threadlinqs.com/threat/TL-2026-2476) — high — 2026-09-13
- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Coordinated GitHub API Enumeration and Access Token Abuse Campaign](https://intel.threadlinqs.com/threat/TL-2026-2339) — high — 2026-09-05
- [Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…](https://intel.threadlinqs.com/threat/TL-2026-2280) — medium — 2026-08-28
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…](https://intel.threadlinqs.com/threat/TL-2026-2107) — critical — 2026-08-22
- [Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS](https://intel.threadlinqs.com/threat/TL-2026-2028) — high — 2026-08-16
- ["TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…](https://intel.threadlinqs.com/threat/TL-2026-2027) — high — 2026-08-16
- [OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio…](https://intel.threadlinqs.com/threat/TL-2026-2018) — high — 2026-08-14
- [Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)](https://intel.threadlinqs.com/threat/TL-2026-2009) — medium — 2026-08-13
- [AWS IAM Privilege Escalation Attack Path via iam:CreateAccessKey, iam:UpdateLoginProfile, and…](https://intel.threadlinqs.com/threat/TL-2026-2000) — medium — 2026-08-12
- [Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise](https://intel.threadlinqs.com/threat/TL-2026-1970) — high — 2026-08-10
- [Metabase Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited in the Wild for Unauthenticated Admin Access](https://intel.threadlinqs.com/threat/TL-2026-1940) — critical — 2026-08-08
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…](https://intel.threadlinqs.com/threat/TL-2026-1930) — high — 2026-08-07
- [Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens](https://intel.threadlinqs.com/threat/TL-2026-1873) — high — 2026-08-04
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1871) — high — 2026-08-04
- [Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud](https://intel.threadlinqs.com/threat/TL-2026-1826) — low — 2026-08-03
- [CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence](https://intel.threadlinqs.com/threat/TL-2026-1825) — high — 2026-08-03
- [CosmosEscape: Azure Cosmos DB Gremlin Sandbox Escape Exposed Platform-Wide Master Key (CVE-2026-66803)](https://intel.threadlinqs.com/threat/TL-2026-1779) — critical — 2026-07-30
- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — high — 2026-07-22
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…](https://intel.threadlinqs.com/threat/TL-2026-1342) — high — 2026-07-14
- [ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access](https://intel.threadlinqs.com/threat/TL-2026-1311) — high — 2026-07-14
- [Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths…](https://intel.threadlinqs.com/threat/TL-2026-1288) — high — 2026-07-14

## Related CVEs

CVEs referenced by the tracked threats that use T1087.004, most frequent first.

- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2025-62554](https://intel.threadlinqs.com/cve/CVE-2025-62554)
- [CVE-2025-62557](https://intel.threadlinqs.com/cve/CVE-2025-62557)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-66803](https://intel.threadlinqs.com/cve/CVE-2026-66803)
- [CVE-2026-69836](https://intel.threadlinqs.com/cve/CVE-2026-69836)

## Detection coverage

Threadlinqs maintains 87 detection rules mapped to T1087.004 (SPL 30, KQL 33, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.

87 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1087 Account Discovery](https://intel.threadlinqs.com/technique/T1087) — 339 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1087.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
