Activity timeline
T1136.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 5 reports, and 17 of the 17 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1136.002 Domain Account is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix, as a sub-technique of T1136 Create Account. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 11 critical, 6 high.
Threats that use T1136.002 most often also use T1190 Exploit Public-Facing Application (13 threats), T1018 Remote System Discovery (12 threats), T1219 Remote Access Tools (12 threats), T1087.002 Domain Account (11 threats), T1572 Protocol Tunneling (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use T1136.002; the most frequent are Akira (2), Storm-1567 (2), Storm-1175 (1), The Gentlemen (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1136.002.
Data sources
Telemetry that can reveal T1136.002, per MITRE ATT&CK.
- Command — Command Execution
- Process — Process Creation
- User Account — User Account Creation
Threat actors using it
Tracked threats
17 tracked threats use T1136.002.
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…critical
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…high
- N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…high
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeovercritical
- CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonationcritical
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…high
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Added to CISA KEVhigh
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)critical
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and…critical
- BeyondTrust Remote Support & PRA Pre-Authentication Remote Code Execution via OS Command Injection…critical
- BeyondTrust Pre-Auth RCE (CVE-2026-1731) — CVSS 9.9, CISA KEV, WebSocket Command Injection, VShell/SparkRAT…critical
- CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS…critical
- Ransomware Threat Landscape 2025-2027 — RaaS Destabilization, Conti Leak Cascade, ESXi Hypervisor Targeting…critical
Detection coverage
Threadlinqs maintains 23 detection rules mapped to T1136.002 (SPL 10, KQL 7, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1136 Create Account — 152 tracked threats at the technique level.