# T1134 Access Token Manipulation

> As of 2026-10-05, T1134 (Access Token Manipulation) appears in 83 tracked threats, first reported 2026-02-02 and most recently 2026-09-23, with linked actors including Nightmare Eclipse, Chaotic Eclipse, Nightmare-Eclipse; it most often appears alongside T1685 (Disable or Modify Tools).

- **Tracked threats:** 83 (26 critical, 47 high, 10 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-23
- **Threat actors:** 41
- **Detection rules:** 43 (counts only; Blue tier and above)

## Key facts

- **ID:** T1134
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1134/

## Activity timeline

T1134 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-23. The busiest month was 2026-07 with 39 reports, and 83 of the 83 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1134 Access Token Manipulation is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 83 of 2623 tracked threats (3.2%) to it; by severity that is 26 critical, 47 high, 10 medium.

Threats that use T1134 most often also use [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (51 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (50 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (49 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (44 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

41 tracked threat actors appear in the threats that use T1134; the most frequent are [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (7), [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (3), [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) (3), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (2).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1134.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)

## Data sources

Telemetry that can reveal T1134, per MITRE ATT&CK.

- Active Directory — Active Directory Object Modification
- Command — Command Execution
- Process — OS API Execution, Process Creation, Process Metadata
- User Account — User Account Metadata

## Threat actors using it

- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 7
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 3
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 3
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 2
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 2
- [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse) — 2
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 2
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1

## Tracked threats

The 30 most recent of 83 tracked threats that use T1134.

- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…](https://intel.threadlinqs.com/threat/TL-2026-2469) — medium — 2026-09-12
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…](https://intel.threadlinqs.com/threat/TL-2026-2325) — high — 2026-09-04
- [ShieldBreak: Windows Defender Cloud-Hydration Zero-Day Bypasses RoguePlanet Patch (CVE-2026-50656) for…](https://intel.threadlinqs.com/threat/TL-2026-2020) — critical — 2026-08-14
- [DeadLock Ransomware: Rust-Based Encryptor with Decentralized Recovery Infrastructure on Polygon and Session](https://intel.threadlinqs.com/threat/TL-2026-1981) — high — 2026-08-10
- [BINDCLOAK Backdoor Campaign Targeting Middle East Government Entities](https://intel.threadlinqs.com/threat/TL-2026-1844) — high — 2026-08-03
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed](https://intel.threadlinqs.com/threat/TL-2026-1742) — high — 2026-07-28
- [Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags…](https://intel.threadlinqs.com/threat/TL-2026-1735) — medium — 2026-07-28
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…](https://intel.threadlinqs.com/threat/TL-2026-1729) — critical — 2026-07-27
- [UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…](https://intel.threadlinqs.com/threat/TL-2026-1726) — medium — 2026-07-27
- [CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-1707) — high — 2026-07-26
- [Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkit](https://intel.threadlinqs.com/threat/TL-2026-1754) — high — 2026-07-25
- [BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1678) — high — 2026-07-24
- [DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)](https://intel.threadlinqs.com/threat/TL-2026-1647) — high — 2026-07-23
- [Kootenai County, Idaho Ransomware Attack Exposes Resident Personal Information](https://intel.threadlinqs.com/threat/TL-2026-1640) — medium — 2026-07-22
- [RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan…](https://intel.threadlinqs.com/threat/TL-2026-1639) — high — 2026-07-22
- ["LegacyHive" Windows User Profile Service Zero-Day Allows Non-Admin Registry Hive Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1585) — high — 2026-07-21
- [ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage](https://intel.threadlinqs.com/threat/TL-2026-1558) — high — 2026-07-20
- [TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain](https://intel.threadlinqs.com/threat/TL-2026-1557) — high — 2026-07-20
- [LegacyHive: Local Privilege Escalation PoC via Windows User Profile Service (ProfSvc) Registry Hive Mounting](https://intel.threadlinqs.com/threat/TL-2026-1499) — medium — 2026-07-18
- [HTA-Based Cobalt Strike Downloader Script Analysis (CyberChef Deobfuscation)](https://intel.threadlinqs.com/threat/TL-2026-1482) — medium — 2026-07-18
- [Spirals Ransomware — New Rust-Based Family Breaches Internet-Facing IIS Server, Encrypts Entire Domain…](https://intel.threadlinqs.com/threat/TL-2026-1481) — critical — 2026-07-18
- [Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565…](https://intel.threadlinqs.com/threat/TL-2026-1474) — high — 2026-07-18
- [Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver…](https://intel.threadlinqs.com/threat/TL-2026-1453) — high — 2026-07-17
- [LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…](https://intel.threadlinqs.com/threat/TL-2026-1449) — high — 2026-07-17
- [LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public…](https://intel.threadlinqs.com/threat/TL-2026-1445) — high — 2026-07-17
- [Spirals Ransomware: Rust-Based Double Extortion Campaign Against South Asian IT Company](https://intel.threadlinqs.com/threat/TL-2026-2399) — critical — 2026-07-16
- [TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chain](https://intel.threadlinqs.com/threat/TL-2026-1420) — high — 2026-07-16

## Related CVEs

CVEs referenced by the tracked threats that use T1134, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-21514](https://intel.threadlinqs.com/cve/CVE-2026-21514)
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519)
- [CVE-2026-21522](https://intel.threadlinqs.com/cve/CVE-2026-21522)
- [CVE-2026-21525](https://intel.threadlinqs.com/cve/CVE-2026-21525)
- [CVE-2026-21532](https://intel.threadlinqs.com/cve/CVE-2026-21532)
- [CVE-2026-21533](https://intel.threadlinqs.com/cve/CVE-2026-21533)
- [CVE-2026-23655](https://intel.threadlinqs.com/cve/CVE-2026-23655)

## Detection coverage

Threadlinqs maintains 43 detection rules mapped to T1134 (SPL 14, KQL 19, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

43 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1134.001 Token Impersonation/Theft](https://intel.threadlinqs.com/technique/T1134.001) — 19 tracked threats
- [T1134.002 Create Process with Token](https://intel.threadlinqs.com/technique/T1134.002) — 13 tracked threats
- T1134.003 Make and Impersonate Token — 7 tracked threats
- T1134.004 Parent PID Spoofing — 5 tracked threats
- T1134.005 SID-History Injection — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1134
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
