Activity timeline
T1585.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 38 reports, and 87 of the 87 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1585.001 Social Media Accounts is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1585 Establish Accounts. Threadlinqs maps 87 of 2623 tracked threats (3.3%) to it; by severity that is 4 critical, 63 high, 18 medium, 2 low.
Threats that use T1585.001 most often also use T1204.002 Malicious File (53 threats), T1071.001 Web Protocols (51 threats), T1005 Data from Local System (46 threats), T1583.001 Domains (46 threats), T1566.002 Spearphishing Link (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
34 tracked threat actors appear in the threats that use T1585.001; the most frequent are WageMole (7), APT38 (6), Lazarus Group (6), Andariel (5), Contagious Interview (5).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1585.001.
Data sources
Telemetry that can reveal T1585.001, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content
- Persona — Social Media
Threat actors using it
Tracked threats
The 30 most recent of 87 tracked threats that use T1585.001.
- Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…high
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFAhigh
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…medium
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Scriptmedium
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Usersmedium
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- UK establishes National Centre for Information Defence to counter Russian state disinformation operationshigh
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
- indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()high
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…high
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Softwarehigh
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2high
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- "Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAshigh
- DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Networkmedium
- Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Timelow
- FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial…high
- "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…high
- CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…high
- Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detectionhigh
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…high
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)high
- AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape…high
- UAC-0145 (Sandworm/APT44) Trojanizes WireGuard VPN Client 'SopraVPN' via Fake IT Recruitment Schemehigh
- UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign…high
- Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraudlow
- LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"medium
- Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…high
Detection coverage
Threadlinqs maintains 50 detection rules mapped to T1585.001 (SPL 13, KQL 14, Sigma 23). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1585 Establish Accounts — 250 tracked threats at the technique level.