# T1098.005 Device Registration

> As of 2026-10-05, T1098.005 (Device Registration) appears in 28 tracked threats, first reported 2026-02-16 and most recently 2026-10-03, with linked actors including Greatness PhaaS Operators, Kali365 PhaaS operators, ShinyHunters; it most often appears alongside T1566.002 (Spearphishing Link).

- **Tracked threats:** 28 (2 critical, 23 high, 3 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-03
- **Threat actors:** 19
- **Detection rules:** 106 (counts only; Blue tier and above)

## Key facts

- **ID:** T1098.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1098
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1098/005/

## Activity timeline

T1098.005 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 9 reports, and 28 of the 28 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1098.005 Device Registration is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098). Threadlinqs maps 28 of 2623 tracked threats (1.1%) to it; by severity that is 2 critical, 23 high, 3 medium.

Threats that use T1098.005 most often also use [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (21 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (20 threats), [T1550.001 Application Access Token](https://intel.threadlinqs.com/technique/T1550.001) (19 threats), [T1078.004 Cloud Accounts](https://intel.threadlinqs.com/technique/T1078.004) (16 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

19 tracked threat actors appear in the threats that use T1098.005; the most frequent are [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) (3), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (2), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (2), [Storm-2992](https://intel.threadlinqs.com/actor/Storm-2992) (2), [APT29](https://intel.threadlinqs.com/actor/APT29) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1098.005.

- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1098.005, per MITRE ATT&CK.

- Active Directory — Active Directory Object Creation
- Application Log — Application Log Content
- User Account — User Account Modification

## Threat actors using it

- [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) — 3
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 2
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2
- [Storm-2992](https://intel.threadlinqs.com/actor/Storm-2992) — 2
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) — 1
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 1
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 1
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 1

## Tracked threats

28 tracked threats use T1098.005.

- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2873) — high — 2026-10-03
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — medium — 2026-09-25
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EU](https://intel.threadlinqs.com/threat/TL-2026-2537) — high — 2026-09-16
- [Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…](https://intel.threadlinqs.com/threat/TL-2026-2280) — medium — 2026-08-28
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…](https://intel.threadlinqs.com/threat/TL-2026-2091) — high — 2026-08-21
- [Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra ID](https://intel.threadlinqs.com/threat/TL-2026-1952) — high — 2026-08-09
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1926) — high — 2026-08-07
- [QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day…](https://intel.threadlinqs.com/threat/TL-2026-2893) — high — 2026-08-06
- [Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens](https://intel.threadlinqs.com/threat/TL-2026-1873) — high — 2026-08-04
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1871) — high — 2026-08-04
- [Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication](https://intel.threadlinqs.com/threat/TL-2026-1842) — critical — 2026-08-03
- [Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1814) — high — 2026-07-29
- [Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brands](https://intel.threadlinqs.com/threat/TL-2026-1731) — medium — 2026-07-27
- [Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809…](https://intel.threadlinqs.com/threat/TL-2026-1705) — critical — 2026-07-26
- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — high — 2026-07-22
- [Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abuse](https://intel.threadlinqs.com/threat/TL-2026-1492) — high — 2026-07-18
- [Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta…](https://intel.threadlinqs.com/threat/TL-2026-1258) — high — 2026-07-13
- [O-UNC-066 ("Pink") Abuses Microsoft Entra Passkey Enrollment via Live-Operator Phone Phishing to Hijack…](https://intel.threadlinqs.com/threat/TL-2026-1186) — high — 2026-07-10
- [ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1037) — high — 2026-07-01
- [ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1036) — high — 2026-07-01
- [EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…](https://intel.threadlinqs.com/threat/TL-2026-0888) — high — 2026-06-20
- [Dashlane Device-Registration API 2FA OTP Brute-Force Campaign — Encrypted Vaults of <20 Personal-Plan…](https://intel.threadlinqs.com/threat/TL-2026-0705) — high — 2026-06-07
- [VaultJacking — Google Password Manager Vault Theft via Single Captured 6-Digit PIN (PhishU Framework)](https://intel.threadlinqs.com/threat/TL-2026-0620) — high — 2026-05-28
- [Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0560) — high — 2026-05-22
- [State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database…](https://intel.threadlinqs.com/threat/TL-2026-0111) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1098.005, most frequent first.

- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-34348](https://intel.threadlinqs.com/cve/CVE-2026-34348)

## Detection coverage

Threadlinqs maintains 106 detection rules mapped to T1098.005 (SPL 36, KQL 35, Sigma 35). Rule content is available to Blue tier accounts and above; this page shows counts only.

106 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098) — 288 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1098.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
