# T1098.003 Additional Cloud Roles

> As of 2026-10-05, T1098.003 (Additional Cloud Roles) appears in 19 tracked threats, first reported 2026-02-16 and most recently 2026-10-03, with linked actors including Scattered Spider, Kali365, Kali365 PhaaS operators; it most often appears alongside T1078.004 (Cloud Accounts).

- **Tracked threats:** 19 (8 critical, 9 high, 2 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-03
- **Threat actors:** 7
- **Detection rules:** 40 (counts only; Blue tier and above)

## Key facts

- **ID:** T1098.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1098
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1098/003/

## Activity timeline

T1098.003 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 7 reports, and 19 of the 19 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1098.003 Additional Cloud Roles is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098). Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 8 critical, 9 high, 2 medium.

Threats that use T1098.003 most often also use [T1078.004 Cloud Accounts](https://intel.threadlinqs.com/technique/T1078.004) (15 threats), [T1550.001 Application Access Token](https://intel.threadlinqs.com/technique/T1550.001) (11 threats), [T1087.004 Cloud Account](https://intel.threadlinqs.com/technique/T1087.004) (10 threats), [T1199 Trusted Relationship](https://intel.threadlinqs.com/technique/T1199) (10 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1098.003; the most frequent are [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (2), [Kali365](https://intel.threadlinqs.com/actor/Kali365) (1), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (1), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (1), [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1098.003.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1098.003, per MITRE ATT&CK.

- User Account — User Account Modification

## Threat actors using it

- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 2
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 1
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 1
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 1
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 1

## Tracked threats

19 tracked threats use T1098.003.

- [AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2860) — critical — 2026-10-03
- [ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize…](https://intel.threadlinqs.com/threat/TL-2026-2629) — critical — 2026-09-23
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…](https://intel.threadlinqs.com/threat/TL-2026-2107) — critical — 2026-08-22
- [AWS IAM Privilege Escalation Attack Path via iam:CreateAccessKey, iam:UpdateLoginProfile, and…](https://intel.threadlinqs.com/threat/TL-2026-2000) — medium — 2026-08-12
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [Google Ads MMC Sync Phishing Campaign Uses Fake Maintenance Notices for Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-2535) — medium — 2026-07-21
- [Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1584) — high — 2026-07-21
- [Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecraft](https://intel.threadlinqs.com/threat/TL-2026-1333) — high — 2026-07-14
- [ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access](https://intel.threadlinqs.com/threat/TL-2026-1311) — high — 2026-07-14
- [Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths…](https://intel.threadlinqs.com/threat/TL-2026-1288) — high — 2026-07-14
- [Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1161) — high — 2026-07-10
- [BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1060) — high — 2026-07-02
- [Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign](https://intel.threadlinqs.com/threat/TL-2026-0984) — critical — 2026-06-28
- [Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines…](https://intel.threadlinqs.com/threat/TL-2026-0928) — critical — 2026-06-23
- [Ivanti Neurons for ITSM CVE-2026-9614 — Improper Access Control Privilege Escalation to Administrator](https://intel.threadlinqs.com/threat/TL-2026-0676) — high — 2026-06-03
- [Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0560) — high — 2026-05-22
- [Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…](https://intel.threadlinqs.com/threat/TL-2026-0548) — critical — 2026-05-21
- [Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0529) — critical — 2026-05-19
- [CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS…](https://intel.threadlinqs.com/threat/TL-2026-0110) — critical — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1098.003, most frequent first.

- [CVE-2024-12356](https://intel.threadlinqs.com/cve/CVE-2024-12356)
- [CVE-2024-12686](https://intel.threadlinqs.com/cve/CVE-2024-12686)
- [CVE-2025-1094](https://intel.threadlinqs.com/cve/CVE-2025-1094)
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2025-62554](https://intel.threadlinqs.com/cve/CVE-2025-62554)
- [CVE-2025-62557](https://intel.threadlinqs.com/cve/CVE-2025-62557)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-69836](https://intel.threadlinqs.com/cve/CVE-2026-69836)

## Detection coverage

Threadlinqs maintains 40 detection rules mapped to T1098.003 (SPL 16, KQL 12, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

40 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098) — 288 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1098.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
