Activity timeline
T1136 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 62 reports, and 152 of the 152 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1136 Create Account is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix. Threadlinqs maps 152 of 2623 tracked threats (5.8%) to it; by severity that is 95 critical, 51 high, 5 medium.
Threats that use T1136 most often also use T1190 Exploit Public-Facing Application (125 threats), T1059 Command and Scripting Interpreter (115 threats), T1078 Valid Accounts (113 threats), T1098 Account Manipulation (83 threats), T1005 Data from Local System (82 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
53 tracked threat actors appear in the threats that use T1136; the most frequent are Static Tundra (7), FSB Center 16 (4), ShinyHunters (4), INC Ransom (3), INC Ransom - G1032 (3).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1136.
Data sources
Telemetry that can reveal T1136, per MITRE ATT&CK.
- Command — Command Execution
- Process — Process Creation
- User Account — User Account Creation
Threat actors using it
Tracked threats
The 30 most recent of 152 tracked threats that use T1136.
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…high
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affectedcritical
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)critical
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…high
- Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV…critical
- ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs…critical
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodologyhigh
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- Critical Metabase Zero-Day (CVE-2026-72898): Unauthenticated SQL Injection Grants Admin Access, Exploited in…critical
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidentshigh
- FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructurecritical
- WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638)high
- Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command…critical
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeovercritical
- Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…medium
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…critical
- Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)critical
- Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…critical
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Accessmedium
- AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…high
- Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkithigh
Detection coverage
Threadlinqs maintains 102 detection rules mapped to T1136 (SPL 34, KQL 35, Sigma 33). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1136.001 Local Account — 73 tracked threats
- T1136.002 Domain Account — 17 tracked threats
- T1136.003 Cloud Account — 8 tracked threats