Activity timeline
T1134.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 6 reports, and 19 of the 19 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1134.001 Token Impersonation/Theft is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of T1134 Access Token Manipulation. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 6 critical, 11 high, 2 medium.
Threats that use T1134.001 most often also use T1082 System Information Discovery (14 threats), T1059.003 Windows Command Shell (11 threats), T1027 Obfuscated Files or Information (9 threats), T1005 Data from Local System (7 threats), T1057 Process Discovery (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1134.001; the most frequent are Anubis (1), GhostEmperor (1), Kapibala (1), REvil (1), SHADOW-WATER-063 (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1134.001.
Data sources
Telemetry that can reveal T1134.001, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution
Threat actors using it
Tracked threats
19 tracked threats use T1134.001.
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…critical
- CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry…high
- Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…high
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV…medium
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…high
- PhantomStealer Infostealer Distributed via Phishing Campaign with BYOVD Security Software Killerhigh
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…high
- CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)high
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary…high
- Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil…medium
- Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and…high
- PolinRider: DPRK Supply-Chain Campaign Hides BeaverTail/InvisibleFerret Malware in JS Build Config Files…critical
- AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian…high
- Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host…critical
- Windows Kernel CVE-2026-40369 — NtQuerySystemInformation ProbeForWrite Bypass Enables Arbitrary Kernel…critical
- PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation…high
- Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider…high
Detection coverage
Threadlinqs maintains 48 detection rules mapped to T1134.001 (SPL 15, KQL 19, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1134 Access Token Manipulation — 83 tracked threats at the technique level.