# T1134.001 Token Impersonation/Theft

> As of 2026-10-05, T1134.001 (Token Impersonation/Theft) appears in 19 tracked threats, first reported 2026-03-01 and most recently 2026-09-28, with linked actors including Anubis, GhostEmperor, Kapibala; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 19 (6 critical, 11 high, 2 medium)
- **First seen:** 2026-03-01
- **Last seen:** 2026-09-28
- **Threat actors:** 8
- **Detection rules:** 48 (counts only; Blue tier and above)

## Key facts

- **ID:** T1134.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1134
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1134/001/

## Activity timeline

T1134.001 first appeared in tracked threats on 2026-03-01 and was most recently reported on 2026-09-28. The busiest month was 2026-08 with 6 reports, and 19 of the 19 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1134.001 Token Impersonation/Theft is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of [T1134 Access Token Manipulation](https://intel.threadlinqs.com/technique/T1134). Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 6 critical, 11 high, 2 medium.

Threats that use T1134.001 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (14 threats), [T1059.003 Windows Command Shell](https://intel.threadlinqs.com/technique/T1059.003) (11 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (9 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (7 threats), [T1057 Process Discovery](https://intel.threadlinqs.com/technique/T1057) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1134.001; the most frequent are [Anubis](https://intel.threadlinqs.com/actor/Anubis) (1), [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (1), [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) (1), [REvil](https://intel.threadlinqs.com/actor/REvil) (1), [SHADOW-WATER-063](https://intel.threadlinqs.com/actor/SHADOW-WATER-063) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1134.001.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)

## Data sources

Telemetry that can reveal T1134.001, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution

## Threat actors using it

- [Anubis](https://intel.threadlinqs.com/actor/Anubis) — 1
- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 1
- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1
- [REvil](https://intel.threadlinqs.com/actor/REvil) — 1
- [SHADOW-WATER-063](https://intel.threadlinqs.com/actor/SHADOW-WATER-063) — 1
- [Safepay](https://intel.threadlinqs.com/actor/Safepay) — 1
- [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) — 1
- [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945) — 1

## Tracked threats

19 tracked threats use T1134.001.

- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…](https://intel.threadlinqs.com/threat/TL-2026-2619) — critical — 2026-09-22
- [CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry…](https://intel.threadlinqs.com/threat/TL-2026-2480) — high — 2026-09-13
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV…](https://intel.threadlinqs.com/threat/TL-2026-2136) — medium — 2026-08-24
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…](https://intel.threadlinqs.com/threat/TL-2026-2096) — high — 2026-08-21
- [PhantomStealer Infostealer Distributed via Phishing Campaign with BYOVD Security Software Killer](https://intel.threadlinqs.com/threat/TL-2026-2055) — high — 2026-08-18
- [CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…](https://intel.threadlinqs.com/threat/TL-2026-1857) — high — 2026-08-04
- [CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-1707) — high — 2026-07-26
- [Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary…](https://intel.threadlinqs.com/threat/TL-2026-1615) — high — 2026-07-22
- [Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil…](https://intel.threadlinqs.com/threat/TL-2026-1446) — medium — 2026-07-17
- [Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and…](https://intel.threadlinqs.com/threat/TL-2026-1080) — high — 2026-07-02
- [PolinRider: DPRK Supply-Chain Campaign Hides BeaverTail/InvisibleFerret Malware in JS Build Config Files…](https://intel.threadlinqs.com/threat/TL-2026-1143) — critical — 2026-06-21
- [AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian…](https://intel.threadlinqs.com/threat/TL-2026-0841) — high — 2026-06-17
- [Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host…](https://intel.threadlinqs.com/threat/TL-2026-0694) — critical — 2026-06-06
- [Windows Kernel CVE-2026-40369 — NtQuerySystemInformation ProbeForWrite Bypass Enables Arbitrary Kernel…](https://intel.threadlinqs.com/threat/TL-2026-0604) — critical — 2026-05-27
- [PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation…](https://intel.threadlinqs.com/threat/TL-2026-0420) — high — 2026-04-24
- [Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider…](https://intel.threadlinqs.com/threat/TL-2026-0161) — high — 2026-03-01

## Related CVEs

CVEs referenced by the tracked threats that use T1134.001, most frequent first.

- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2017-11317](https://intel.threadlinqs.com/cve/CVE-2017-11317)
- [CVE-2019-16098](https://intel.threadlinqs.com/cve/CVE-2019-16098)
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-37042](https://intel.threadlinqs.com/cve/CVE-2022-37042)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-40369](https://intel.threadlinqs.com/cve/CVE-2026-40369)
- [CVE-2026-42980](https://intel.threadlinqs.com/cve/CVE-2026-42980)
- [CVE-2026-56271](https://intel.threadlinqs.com/cve/CVE-2026-56271)
- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-7273](https://intel.threadlinqs.com/cve/CVE-2026-7273)

## Detection coverage

Threadlinqs maintains 48 detection rules mapped to T1134.001 (SPL 15, KQL 19, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.

48 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1134 Access Token Manipulation](https://intel.threadlinqs.com/technique/T1134) — 83 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1134.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
