Activity timeline
T1098.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 7 reports, and 19 of the 19 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1098.003 Additional Cloud Roles is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1098 Account Manipulation. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 8 critical, 9 high, 2 medium.
Threats that use T1098.003 most often also use T1078.004 Cloud Accounts (15 threats), T1550.001 Application Access Token (11 threats), T1087.004 Cloud Account (10 threats), T1199 Trusted Relationship (10 threats), T1528 Steal Application Access Token (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1098.003; the most frequent are Scattered Spider (2), Kali365 (1), Kali365 PhaaS operators (1), ShinyHunters (1), UNC6040 (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1098.003.
Data sources
Telemetry that can reveal T1098.003, per MITRE ATT&CK.
- User Account — User Account Modification
Threat actors using it
Tracked threats
19 tracked threats use T1098.003.
- AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…critical
- ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize…critical
- CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…critical
- AWS IAM Privilege Escalation Attack Path via iam:CreateAccessKey, iam:UpdateLoginProfile, and…medium
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidentshigh
- Google Ads MMC Sync Phishing Campaign Uses Fake Maintenance Notices for Credential Theftmedium
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass…high
- Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecrafthigh
- ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Accesshigh
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths…high
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…high
- BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege…high
- Kali365/Octopi365 Device Code Phishing-as-a-Service Campaigncritical
- Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines…critical
- Ivanti Neurons for ITSM CVE-2026-9614 — Improper Access Control Privilege Escalation to Administratorhigh
- Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass…high
- Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…critical
- Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltrationcritical
- CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS…critical
Detection coverage
Threadlinqs maintains 40 detection rules mapped to T1098.003 (SPL 16, KQL 12, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1098 Account Manipulation — 288 tracked threats at the technique level.