# T1585.002 Email Accounts

> As of 2026-10-05, T1585.002 (Email Accounts) appears in 53 tracked threats, first reported 2026-02-22 and most recently 2026-10-04, with linked actors including APT32, APT38, Kali365; it most often appears alongside T1566.002 (Spearphishing Link).

- **Tracked threats:** 53 (3 critical, 28 high, 21 medium, 1 low)
- **First seen:** 2026-02-22
- **Last seen:** 2026-10-04
- **Threat actors:** 11
- **Detection rules:** 82 (counts only; Blue tier and above)

## Key facts

- **ID:** T1585.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1585
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1585/002/

## Activity timeline

T1585.002 first appeared in tracked threats on 2026-02-22 and was most recently reported on 2026-10-04. The busiest month was 2026-09 with 15 reports, and 53 of the 53 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1585.002 Email Accounts is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1585 Establish Accounts](https://intel.threadlinqs.com/technique/T1585). Threadlinqs maps 53 of 2623 tracked threats (2%) to it; by severity that is 3 critical, 28 high, 21 medium, 1 low.

Threats that use T1585.002 most often also use [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (35 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (32 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (32 threats), [T1583.006 Web Services](https://intel.threadlinqs.com/technique/T1583.006) (24 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

11 tracked threat actors appear in the threats that use T1585.002; the most frequent are [APT32](https://intel.threadlinqs.com/actor/APT32) (1), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Kali365](https://intel.threadlinqs.com/actor/Kali365) (1), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) (1), [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1585.002.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [APT32](https://intel.threadlinqs.com/actor/APT32) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Kali365](https://intel.threadlinqs.com/actor/Kali365) — 1
- [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators) — 1
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [Storm-1167](https://intel.threadlinqs.com/actor/Storm-1167) — 1
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 1
- [UNC3753](https://intel.threadlinqs.com/actor/UNC3753) — 1

## Tracked threats

The 30 most recent of 53 tracked threats that use T1585.002.

- [Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC](https://intel.threadlinqs.com/threat/TL-2026-2891) — medium — 2026-10-04
- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [UK establishes National Centre for Information Defence to counter Russian state disinformation operations](https://intel.threadlinqs.com/threat/TL-2026-2638) — high — 2026-09-24
- [Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…](https://intel.threadlinqs.com/threat/TL-2026-2567) — medium — 2026-09-18
- [Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details](https://intel.threadlinqs.com/threat/TL-2026-2562) — medium — 2026-09-18
- [Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow](https://intel.threadlinqs.com/threat/TL-2026-2556) — medium — 2026-09-18
- [Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…](https://intel.threadlinqs.com/threat/TL-2026-2548) — medium — 2026-09-17
- [ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Lure](https://intel.threadlinqs.com/threat/TL-2026-2594) — medium — 2026-09-14
- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks](https://intel.threadlinqs.com/threat/TL-2026-2471) — high — 2026-09-12
- [OpenAI Agent Swarm ("GemStuffer") Flooded RubyGems With 2,000+ Malicious Packages, Achieved RCE on…](https://intel.threadlinqs.com/threat/TL-2026-2459) — high — 2026-09-12
- [Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)](https://intel.threadlinqs.com/threat/TL-2026-2451) — medium — 2026-09-11
- [Invisible Unicode Tag Characters Used to Evade Phishing Detection in Financial Scam Campaign](https://intel.threadlinqs.com/threat/TL-2026-2331) — high — 2026-09-04
- ["Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAs](https://intel.threadlinqs.com/threat/TL-2026-2322) — high — 2026-09-03
- [DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network](https://intel.threadlinqs.com/threat/TL-2026-2309) — medium — 2026-09-03
- [Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-2299) — medium — 2026-09-02
- [Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time](https://intel.threadlinqs.com/threat/TL-2026-2289) — low — 2026-09-02
- [Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofing](https://intel.threadlinqs.com/threat/TL-2026-2230) — high — 2026-08-30
- [Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts](https://intel.threadlinqs.com/threat/TL-2026-2167) — high — 2026-08-27
- [AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypass](https://intel.threadlinqs.com/threat/TL-2026-2164) — high — 2026-08-27
- [Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access](https://intel.threadlinqs.com/threat/TL-2026-2129) — medium — 2026-08-24
- [Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)](https://intel.threadlinqs.com/threat/TL-2026-2109) — high — 2026-08-21
- [Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry](https://intel.threadlinqs.com/threat/TL-2026-2088) — high — 2026-08-20
- [Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains](https://intel.threadlinqs.com/threat/TL-2026-2050) — high — 2026-08-17
- [AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub…](https://intel.threadlinqs.com/threat/TL-2026-2042) — medium — 2026-08-17
- [ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers](https://intel.threadlinqs.com/threat/TL-2026-2007) — medium — 2026-08-13
- [UAC-0145 (Sandworm/APT44) Trojanizes WireGuard VPN Client 'SopraVPN' via Fake IT Recruitment Scheme](https://intel.threadlinqs.com/threat/TL-2026-1994) — high — 2026-08-12
- [CVE-2026-70329: Microsoft Outlook Remote Code Execution via Integer Overflow](https://intel.threadlinqs.com/threat/TL-2026-1991) — high — 2026-08-11
- [U.S. Defense Manufacturer IEH Corporation Breached via Phishing, Potential Export-Controlled Data Exposure](https://intel.threadlinqs.com/threat/TL-2026-1960) — high — 2026-08-09
- [AI Agent (Claude Mythos 5) Publishes Credential-Stealing Package 'mlflow-ui' to PyPI During Cyber…](https://intel.threadlinqs.com/threat/TL-2026-2747) — high — 2026-07-30

## Related CVEs

CVEs referenced by the tracked threats that use T1585.002, most frequent first.

- [CVE-2026-70329](https://intel.threadlinqs.com/cve/CVE-2026-70329)

## Detection coverage

Threadlinqs maintains 82 detection rules mapped to T1585.002 (SPL 33, KQL 30, Sigma 19). Rule content is available to Blue tier accounts and above; this page shows counts only.

82 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1585 Establish Accounts](https://intel.threadlinqs.com/technique/T1585) — 250 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1585.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
