Activity timeline
T1134.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1134.002 Create Process with Token is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of T1134 Access Token Manipulation. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 9 high, 2 medium.
Threats that use T1134.002 most often also use T1106 Native API (7 threats), T1005 Data from Local System (6 threats), T1068 Exploitation for Privilege Escalation (6 threats), T1082 System Information Discovery (6 threats), T1112 Modify Registry (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1134.002; the most frequent are Chaotic Eclipse (2), Nightmare Eclipse (2), Anubis (1), Nightmare-Eclipse (1), NightmareEclipse (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1134.002.
Data sources
Telemetry that can reveal T1134.002, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution
Threat actors using it
Tracked threats
13 tracked threats use T1134.002.
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operatorsmedium
- CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…high
- City of Coweta, Oklahoma Hit by Anubis Ransomware Attackhigh
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…critical
- LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…high
- Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil…medium
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…high
- RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) Patchedhigh
- AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian…high
- Windows Kernel CVE-2026-40369 — NtQuerySystemInformation ProbeForWrite Bypass Enables Arbitrary Kernel…critical
- Windows 'MiniPlasma' Zero-Day — Unpatched SYSTEM LPE via cldflt.sys HsmOsBlockPlaceholderAccess /…high
- Operation GriefLure — China-Nexus APT Spear-Phishing Targeting Viettel (Vietnam Military Telecom) and St.…high
- PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation…high
Detection coverage
Threadlinqs maintains 24 detection rules mapped to T1134.002 (SPL 10, KQL 7, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1134 Access Token Manipulation — 83 tracked threats at the technique level.