Activity timeline
T1585.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 15 reports, and 53 of the 53 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1585.002 Email Accounts is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1585 Establish Accounts. Threadlinqs maps 53 of 2623 tracked threats (2%) to it; by severity that is 3 critical, 28 high, 21 medium, 1 low.
Threats that use T1585.002 most often also use T1566.002 Spearphishing Link (35 threats), T1583.001 Domains (32 threats), T1684.001 Impersonation (32 threats), T1583.006 Web Services (24 threats), T1204.001 Malicious Link (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
11 tracked threat actors appear in the threats that use T1585.002; the most frequent are APT32 (1), APT38 (1), Kali365 (1), Kali365 PhaaS operators (1), Luna Moth (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1585.002.
Threat actors using it
Tracked threats
The 30 most recent of 53 tracked threats that use T1585.002.
- Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARCmedium
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)high
- UK establishes National Centre for Information Defence to counter Russian state disinformation operationshigh
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…medium
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Detailsmedium
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flowmedium
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…medium
- ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Luremedium
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networkshigh
- OpenAI Agent Swarm ("GemStuffer") Flooded RubyGems With 2,000+ Malicious Packages, Achieved RCE on…high
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)medium
- Invisible Unicode Tag Characters Used to Evade Phishing Detection in Financial Scam Campaignhigh
- "Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAshigh
- DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Networkmedium
- Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacksmedium
- Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Timelow
- Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofinghigh
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accountshigh
- AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypasshigh
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Accessmedium
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)high
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicryhigh
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chainshigh
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub…medium
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customersmedium
- UAC-0145 (Sandworm/APT44) Trojanizes WireGuard VPN Client 'SopraVPN' via Fake IT Recruitment Schemehigh
- CVE-2026-70329: Microsoft Outlook Remote Code Execution via Integer Overflowhigh
- U.S. Defense Manufacturer IEH Corporation Breached via Phishing, Potential Export-Controlled Data Exposurehigh
- AI Agent (Claude Mythos 5) Publishes Credential-Stealing Package 'mlflow-ui' to PyPI During Cyber…high
Detection coverage
Threadlinqs maintains 82 detection rules mapped to T1585.002 (SPL 33, KQL 30, Sigma 19). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1585 Establish Accounts — 250 tracked threats at the technique level.