Activity timeline
T1134 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 39 reports, and 83 of the 83 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1134 Access Token Manipulation is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 83 of 2623 tracked threats (3.2%) to it; by severity that is 26 critical, 47 high, 10 medium.
Threats that use T1134 most often also use T1685 Disable or Modify Tools (51 threats), T1059 Command and Scripting Interpreter (50 threats), T1082 System Information Discovery (49 threats), T1027 Obfuscated Files or Information (44 threats), T1005 Data from Local System (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
41 tracked threat actors appear in the threats that use T1134; the most frequent are Nightmare Eclipse (7), Chaotic Eclipse (3), Nightmare-Eclipse (3), ALPHV (2), APT28 (2).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1134.
Data sources
Telemetry that can reveal T1134, per MITRE ATT&CK.
- Active Directory — Active Directory Object Modification
- Command — Command Execution
- Process — OS API Execution, Process Creation, Process Metadata
- User Account — User Account Metadata
Threat actors using it
Tracked threats
The 30 most recent of 83 tracked threats that use T1134.
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…high
- ShieldBreak: Windows Defender Cloud-Hydration Zero-Day Bypasses RoguePlanet Patch (CVE-2026-50656) for…critical
- DeadLock Ransomware: Rust-Based Encryptor with Decentralized Recovery Infrastructure on Polygon and Sessionhigh
- BINDCLOAK Backdoor Campaign Targeting Middle East Government Entitieshigh
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installedhigh
- Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags…medium
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…critical
- UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…medium
- CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)high
- Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkithigh
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…high
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)high
- Kootenai County, Idaho Ransomware Attack Exposes Resident Personal Informationmedium
- RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan…high
- "LegacyHive" Windows User Profile Service Zero-Day Allows Non-Admin Registry Hive Hijackinghigh
- ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stagehigh
- TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chainhigh
- LegacyHive: Local Privilege Escalation PoC via Windows User Profile Service (ProfSvc) Registry Hive Mountingmedium
- HTA-Based Cobalt Strike Downloader Script Analysis (CyberChef Deobfuscation)medium
- Spirals Ransomware — New Rust-Based Family Breaches Internet-Facing IIS Server, Encrypts Entire Domain…critical
- Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565…high
- Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver…high
- LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…high
- LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public…high
- Spirals Ransomware: Rust-Based Double Extortion Campaign Against South Asian IT Companycritical
- TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chainhigh
Detection coverage
Threadlinqs maintains 43 detection rules mapped to T1134 (SPL 14, KQL 19, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1134.001 Token Impersonation/Theft — 19 tracked threats
- T1134.002 Create Process with Token — 13 tracked threats
- T1134.003 Make and Impersonate Token — 7 tracked threats
- T1134.004 Parent PID Spoofing — 5 tracked threats
- T1134.005 SID-History Injection — 1 tracked threat