# T1585.001 Social Media Accounts

> As of 2026-10-05, T1585.001 (Social Media Accounts) appears in 87 tracked threats, first reported 2026-02-03 and most recently 2026-10-04, with linked actors including WageMole, APT38, Lazarus Group; it most often appears alongside T1204.002 (Malicious File).

- **Tracked threats:** 87 (4 critical, 63 high, 18 medium, 2 low)
- **First seen:** 2026-02-03
- **Last seen:** 2026-10-04
- **Threat actors:** 34
- **Detection rules:** 50 (counts only; Blue tier and above)

## Key facts

- **ID:** T1585.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1585
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1585/001/

## Activity timeline

T1585.001 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 38 reports, and 87 of the 87 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1585.001 Social Media Accounts is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1585 Establish Accounts](https://intel.threadlinqs.com/technique/T1585). Threadlinqs maps 87 of 2623 tracked threats (3.3%) to it; by severity that is 4 critical, 63 high, 18 medium, 2 low.

Threats that use T1585.001 most often also use [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (53 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (51 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (46 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (46 threats), [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

34 tracked threat actors appear in the threats that use T1585.001; the most frequent are [WageMole](https://intel.threadlinqs.com/actor/WageMole) (7), [APT38](https://intel.threadlinqs.com/actor/APT38) (6), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (6), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (5), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (5).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1585.001.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1585.001, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content
- Persona — Social Media

## Threat actors using it

- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 7
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 5
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 5
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 3
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 3
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 3
- [Iran Ministry of Intelligence](https://intel.threadlinqs.com/actor/Iran%20Ministry%20of%20Intelligence) — 2
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 2
- [Milk Dragon](https://intel.threadlinqs.com/actor/Milk%20Dragon) — 2
- [Security](https://intel.threadlinqs.com/actor/Security) — 2

## Tracked threats

The 30 most recent of 87 tracked threats that use T1585.001.

- [Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…](https://intel.threadlinqs.com/threat/TL-2026-2919) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA](https://intel.threadlinqs.com/threat/TL-2026-2834) — high — 2026-10-01
- [Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a…](https://intel.threadlinqs.com/threat/TL-2026-2770) — medium — 2026-09-29
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — medium — 2026-09-25
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…](https://intel.threadlinqs.com/threat/TL-2026-2650) — critical — 2026-09-25
- [UK establishes National Centre for Information Defence to counter Russian state disinformation operations](https://intel.threadlinqs.com/threat/TL-2026-2638) — high — 2026-09-24
- [Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)](https://intel.threadlinqs.com/threat/TL-2026-2603) — high — 2026-09-21
- [indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()](https://intel.threadlinqs.com/threat/TL-2026-2590) — high — 2026-09-20
- [North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…](https://intel.threadlinqs.com/threat/TL-2026-2581) — high — 2026-09-19
- [KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software](https://intel.threadlinqs.com/threat/TL-2026-2555) — high — 2026-09-17
- [EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2](https://intel.threadlinqs.com/threat/TL-2026-2547) — high — 2026-09-17
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- ["Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAs](https://intel.threadlinqs.com/threat/TL-2026-2322) — high — 2026-09-03
- [DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network](https://intel.threadlinqs.com/threat/TL-2026-2309) — medium — 2026-09-03
- [Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time](https://intel.threadlinqs.com/threat/TL-2026-2289) — low — 2026-09-02
- [FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial…](https://intel.threadlinqs.com/threat/TL-2026-2286) — high — 2026-09-01
- ["The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…](https://intel.threadlinqs.com/threat/TL-2026-2155) — high — 2026-08-26
- [CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-2151) — high — 2026-08-26
- [Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detection](https://intel.threadlinqs.com/threat/TL-2026-2145) — high — 2026-08-25
- [Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…](https://intel.threadlinqs.com/threat/TL-2026-2126) — high — 2026-08-23
- [Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)](https://intel.threadlinqs.com/threat/TL-2026-2109) — high — 2026-08-21
- [AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape…](https://intel.threadlinqs.com/threat/TL-2026-2030) — high — 2026-08-16
- [UAC-0145 (Sandworm/APT44) Trojanizes WireGuard VPN Client 'SopraVPN' via Fake IT Recruitment Scheme](https://intel.threadlinqs.com/threat/TL-2026-1994) — high — 2026-08-12
- [UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign…](https://intel.threadlinqs.com/threat/TL-2026-1973) — high — 2026-08-10
- [Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud](https://intel.threadlinqs.com/threat/TL-2026-1826) — low — 2026-08-03
- [LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"](https://intel.threadlinqs.com/threat/TL-2026-1818) — medium — 2026-08-02
- [Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…](https://intel.threadlinqs.com/threat/TL-2026-1816) — high — 2026-08-02

## Related CVEs

CVEs referenced by the tracked threats that use T1585.001, most frequent first.

- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)
- [CVE-2026-66014](https://intel.threadlinqs.com/cve/CVE-2026-66014)

## Detection coverage

Threadlinqs maintains 50 detection rules mapped to T1585.001 (SPL 13, KQL 14, Sigma 23). Rule content is available to Blue tier accounts and above; this page shows counts only.

50 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1585 Establish Accounts](https://intel.threadlinqs.com/technique/T1585) — 250 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1585.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
