# T1136.001 Local Account

> As of 2026-10-05, T1136.001 (Local Account) appears in 73 tracked threats, first reported 2025-10-13 and most recently 2026-10-01, with linked actors including Static Tundra, DragonForce, JADEPUFFER; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 73 (52 critical, 20 high, 1 medium)
- **First seen:** 2025-10-13
- **Last seen:** 2026-10-01
- **Threat actors:** 10
- **Detection rules:** 172 (counts only; Blue tier and above)

## Key facts

- **ID:** T1136.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence
- **Matrix:** Enterprise
- **Parent:** T1136
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1136/001/

## Activity timeline

T1136.001 first appeared in tracked threats on 2025-10-13 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 30 reports, and 72 of the 73 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1136.001 Local Account is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix, as a sub-technique of [T1136 Create Account](https://intel.threadlinqs.com/technique/T1136). Threadlinqs maps 73 of 2623 tracked threats (2.8%) to it; by severity that is 52 critical, 20 high, 1 medium.

Threats that use T1136.001 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (62 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (40 threats), [T1505.003 Web Shell](https://intel.threadlinqs.com/technique/T1505.003) (37 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (35 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

10 tracked threat actors appear in the threats that use T1136.001; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (3), [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) (2), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) (2), [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) (2), [APT43](https://intel.threadlinqs.com/actor/APT43) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1136.001.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1136.001, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation
- User Account — User Account Creation

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 3
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 2
- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 2
- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) — 1
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 1

## Tracked threats

The 30 most recent of 73 tracked threats that use T1136.001.

- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2688) — critical — 2026-09-27
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…](https://intel.threadlinqs.com/threat/TL-2026-2619) — critical — 2026-09-22
- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…](https://intel.threadlinqs.com/threat/TL-2026-2606) — critical — 2026-09-21
- [CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…](https://intel.threadlinqs.com/threat/TL-2026-2542) — critical — 2026-09-16
- [CVE-2026-27540: Unauthenticated Arbitrary File Upload in WooCommerce Wholesale Lead Capture Plugin Actively…](https://intel.threadlinqs.com/threat/TL-2026-2539) — critical — 2026-09-16
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — medium — 2026-09-13
- [CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCE](https://intel.threadlinqs.com/threat/TL-2026-2440) — critical — 2026-09-10
- [GiveWP WordPress Donation Plugin Flaw (CVE-2026-82222) Lets Attackers Execute Server Commands](https://intel.threadlinqs.com/threat/TL-2026-2188) — critical — 2026-08-28
- [CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2177) — critical — 2026-08-28
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCE](https://intel.threadlinqs.com/threat/TL-2026-2157) — critical — 2026-08-26
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…](https://intel.threadlinqs.com/threat/TL-2026-2153) — high — 2026-08-26
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…](https://intel.threadlinqs.com/threat/TL-2026-2096) — high — 2026-08-21
- [Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813)](https://intel.threadlinqs.com/threat/TL-2026-2092) — critical — 2026-08-20
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2037) — critical — 2026-08-13
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12
- [WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5…](https://intel.threadlinqs.com/threat/TL-2026-1971) — high — 2026-08-10
- [Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1833) — high — 2026-08-03
- [CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)](https://intel.threadlinqs.com/threat/TL-2026-1799) — critical — 2026-07-31
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Kimsuky Group Impersonates Diplomats to Deploy PebbleDash Backdoor and PrxClient Proxy (CVE-less LNK Campaign)](https://intel.threadlinqs.com/threat/TL-2026-1645) — high — 2026-07-22
- [Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk…](https://intel.threadlinqs.com/threat/TL-2026-1638) — critical — 2026-07-22
- [GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for…](https://intel.threadlinqs.com/threat/TL-2026-1579) — critical — 2026-07-20
- [CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password…](https://intel.threadlinqs.com/threat/TL-2026-1568) — high — 2026-07-20

## Related CVEs

CVEs referenced by the tracked threats that use T1136.001, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-48939](https://intel.threadlinqs.com/cve/CVE-2026-48939)
- [CVE-2026-56291](https://intel.threadlinqs.com/cve/CVE-2026-56291)
- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2019-0708](https://intel.threadlinqs.com/cve/CVE-2019-0708)
- [CVE-2019-16098](https://intel.threadlinqs.com/cve/CVE-2019-16098)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)

## Detection coverage

Threadlinqs maintains 172 detection rules mapped to T1136.001 (SPL 65, KQL 65, Sigma 42). Rule content is available to Blue tier accounts and above; this page shows counts only.

172 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1136 Create Account](https://intel.threadlinqs.com/technique/T1136) — 152 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1136.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
