# T1134.002 Create Process with Token

> As of 2026-10-05, T1134.002 (Create Process with Token) appears in 13 tracked threats, first reported 2026-04-24 and most recently 2026-09-16, with linked actors including Chaotic Eclipse, Nightmare Eclipse, Anubis; it most often appears alongside T1106 (Native API).

- **Tracked threats:** 13 (2 critical, 9 high, 2 medium)
- **First seen:** 2026-04-24
- **Last seen:** 2026-09-16
- **Threat actors:** 7
- **Detection rules:** 24 (counts only; Blue tier and above)

## Key facts

- **ID:** T1134.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1134
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1134/002/

## Activity timeline

T1134.002 first appeared in tracked threats on 2026-04-24 and was most recently reported on 2026-09-16. The busiest month was 2026-07 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1134.002 Create Process with Token is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of [T1134 Access Token Manipulation](https://intel.threadlinqs.com/technique/T1134). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 9 high, 2 medium.

Threats that use T1134.002 most often also use [T1106 Native API](https://intel.threadlinqs.com/technique/T1106) (7 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (6 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (6 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (6 threats), [T1112 Modify Registry](https://intel.threadlinqs.com/technique/T1112) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1134.002; the most frequent are [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (2), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (2), [Anubis](https://intel.threadlinqs.com/actor/Anubis) (1), [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) (1), [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1134.002.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)

## Data sources

Telemetry that can reveal T1134.002, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution

## Threat actors using it

- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 2
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 2
- [Anubis](https://intel.threadlinqs.com/actor/Anubis) — 1
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 1
- [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse) — 1
- [REvil](https://intel.threadlinqs.com/actor/REvil) — 1
- [SHADOW-WATER-063](https://intel.threadlinqs.com/actor/SHADOW-WATER-063) — 1

## Tracked threats

13 tracked threats use T1134.002.

- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — medium — 2026-09-16
- [CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…](https://intel.threadlinqs.com/threat/TL-2026-2479) — high — 2026-09-13
- [City of Coweta, Oklahoma Hit by Anubis Ransomware Attack](https://intel.threadlinqs.com/threat/TL-2026-1948) — high — 2026-08-09
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…](https://intel.threadlinqs.com/threat/TL-2026-1729) — critical — 2026-07-27
- [LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…](https://intel.threadlinqs.com/threat/TL-2026-1449) — high — 2026-07-17
- [Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil…](https://intel.threadlinqs.com/threat/TL-2026-1446) — medium — 2026-07-17
- [LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…](https://intel.threadlinqs.com/threat/TL-2026-1373) — high — 2026-07-15
- [RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) Patched](https://intel.threadlinqs.com/threat/TL-2026-1157) — high — 2026-07-10
- [AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian…](https://intel.threadlinqs.com/threat/TL-2026-0841) — high — 2026-06-17
- [Windows Kernel CVE-2026-40369 — NtQuerySystemInformation ProbeForWrite Bypass Enables Arbitrary Kernel…](https://intel.threadlinqs.com/threat/TL-2026-0604) — critical — 2026-05-27
- [Windows 'MiniPlasma' Zero-Day — Unpatched SYSTEM LPE via cldflt.sys HsmOsBlockPlaceholderAccess /…](https://intel.threadlinqs.com/threat/TL-2026-0523) — high — 2026-05-17
- [Operation GriefLure — China-Nexus APT Spear-Phishing Targeting Viettel (Vietnam Military Telecom) and St.…](https://intel.threadlinqs.com/threat/TL-2026-0476) — high — 2026-05-07
- [PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation…](https://intel.threadlinqs.com/threat/TL-2026-0420) — high — 2026-04-24

## Related CVEs

CVEs referenced by the tracked threats that use T1134.002, most frequent first.

- [CVE-2020-17103](https://intel.threadlinqs.com/cve/CVE-2020-17103)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-20817](https://intel.threadlinqs.com/cve/CVE-2026-20817)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-40369](https://intel.threadlinqs.com/cve/CVE-2026-40369)
- [CVE-2026-50656](https://intel.threadlinqs.com/cve/CVE-2026-50656)

## Detection coverage

Threadlinqs maintains 24 detection rules mapped to T1134.002 (SPL 10, KQL 7, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

24 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1134 Access Token Manipulation](https://intel.threadlinqs.com/technique/T1134) — 83 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1134.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
