Activity timeline
T1531 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 63 reports, and 139 of the 139 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1531 Account Access Removal is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 139 of 2623 tracked threats (5.3%) to it; by severity that is 47 critical, 72 high, 18 medium, 2 low.
Threats that use T1531 most often also use T1005 Data from Local System (65 threats), T1190 Exploit Public-Facing Application (60 threats), T1041 Exfiltration Over C2 Channel (56 threats), T1078 Valid Accounts (56 threats), T1539 Steal Web Session Cookie (55 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
59 tracked threat actors appear in the threats that use T1531; the most frequent are TeamPCP (6), Scattered LAPSUS$ Hunters (3), ShinyHunters (3), Void Manticore (3), APT44 (2).
Data sources
Telemetry that can reveal T1531, per MITRE ATT&CK.
- Active Directory — Active Directory Object Modification
- User Account — User Account Deletion, User Account Modification
Threat actors using it
Tracked threats
The 30 most recent of 139 tracked threats that use T1531.
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Scriptmedium
- OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…high
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…high
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…critical
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…critical
- Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug…medium
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…high
- Google Blogger Automated Malware False Positive Locks Hundreds of Blogs — Platform-Wide Enforcement Error…low
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic…high
- Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authenticationcritical
- Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraudlow
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PIImedium
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeyshigh
- Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers…critical
- CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonationcritical
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Datahigh
- AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessionshigh
- CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web…high
- SolarWinds Serv-U 2026.3 Patches 16 Vulnerabilities (CVE-2026-28302 to CVE-2026-28321) Including Root RCE…critical
- Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police…medium
- German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit…high
- International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind…medium
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…high
- Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass…high
- MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys and Credentials via EdgeOne Pageshigh
- UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentialshigh
- CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code…high
- Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abusehigh
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance…critical
Detection coverage
Threadlinqs maintains 74 detection rules mapped to T1531 (SPL 18, KQL 26, Sigma 30). Rule content is available to Blue tier accounts and above; this page shows counts only.