# T1136.002 Domain Account

> As of 2026-10-05, T1136.002 (Domain Account) appears in 17 tracked threats, first reported 2026-02-06 and most recently 2026-09-01, with linked actors including Akira, Storm-1567, Storm-1175; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 17 (11 critical, 6 high)
- **First seen:** 2026-02-06
- **Last seen:** 2026-09-01
- **Threat actors:** 4
- **Detection rules:** 23 (counts only; Blue tier and above)

## Key facts

- **ID:** T1136.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence
- **Matrix:** Enterprise
- **Parent:** T1136
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1136/002/

## Activity timeline

T1136.002 first appeared in tracked threats on 2026-02-06 and was most recently reported on 2026-09-01. The busiest month was 2026-08 with 5 reports, and 17 of the 17 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1136.002 Domain Account is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix, as a sub-technique of [T1136 Create Account](https://intel.threadlinqs.com/technique/T1136). Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 11 critical, 6 high.

Threats that use T1136.002 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (13 threats), [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (12 threats), [T1219 Remote Access Tools](https://intel.threadlinqs.com/technique/T1219) (12 threats), [T1087.002 Domain Account](https://intel.threadlinqs.com/technique/T1087.002) (11 threats), [T1572 Protocol Tunneling](https://intel.threadlinqs.com/technique/T1572) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1136.002; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (2), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (2), [Storm-1175](https://intel.threadlinqs.com/actor/Storm-1175) (1), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1136.002.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1136.002, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation
- User Account — User Account Creation

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 2
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 2
- [Storm-1175](https://intel.threadlinqs.com/actor/Storm-1175) — 1
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1

## Tracked threats

17 tracked threats use T1136.002.

- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…](https://intel.threadlinqs.com/threat/TL-2026-2153) — high — 2026-08-26
- [N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…](https://intel.threadlinqs.com/threat/TL-2026-1941) — high — 2026-08-08
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — critical — 2026-08-03
- [CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation](https://intel.threadlinqs.com/threat/TL-2026-1675) — critical — 2026-07-24
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…](https://intel.threadlinqs.com/threat/TL-2026-1332) — high — 2026-07-14
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1065) — high — 2026-07-02
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — critical — 2026-06-29
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and…](https://intel.threadlinqs.com/threat/TL-2026-0498) — critical — 2026-05-12
- [BeyondTrust Remote Support & PRA Pre-Authentication Remote Code Execution via OS Command Injection…](https://intel.threadlinqs.com/threat/TL-2026-0193) — critical — 2026-03-07
- [BeyondTrust Pre-Auth RCE (CVE-2026-1731) — CVSS 9.9, CISA KEV, WebSocket Command Injection, VShell/SparkRAT…](https://intel.threadlinqs.com/threat/TL-2026-0124) — critical — 2026-02-21
- [CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS…](https://intel.threadlinqs.com/threat/TL-2026-0110) — critical — 2026-02-16
- [Ransomware Threat Landscape 2025-2027 — RaaS Destabilization, Conti Leak Cascade, ESXi Hypervisor Targeting…](https://intel.threadlinqs.com/threat/TL-2026-0115) — critical — 2026-02-06

## Related CVEs

CVEs referenced by the tracked threats that use T1136.002, most frequent first.

- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556)
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577)
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2024-12356](https://intel.threadlinqs.com/cve/CVE-2024-12356)
- [CVE-2024-12686](https://intel.threadlinqs.com/cve/CVE-2024-12686)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-8963](https://intel.threadlinqs.com/cve/CVE-2024-8963)
- [CVE-2025-1094](https://intel.threadlinqs.com/cve/CVE-2025-1094)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)

## Detection coverage

Threadlinqs maintains 23 detection rules mapped to T1136.002 (SPL 10, KQL 7, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

23 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1136 Create Account](https://intel.threadlinqs.com/technique/T1136) — 152 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1136.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
