Activity timeline
T1586 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 54 reports, and 140 of the 140 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1586 Compromise Accounts is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 140 of 2623 tracked threats (5.3%) to it; by severity that is 43 critical, 72 high, 24 medium.
Threats that use T1586 most often also use T1583 Acquire Infrastructure (85 threats), T1027 Obfuscated Files or Information (83 threats), T1005 Data from Local System (80 threats), T1036 Masquerading (73 threats), T1071 Application Layer Protocol (72 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
51 tracked threat actors appear in the threats that use T1586; the most frequent are TeamPCP (19), APT38 (7), Sapphire Sleet (6), Stardust Chollima (6), UNC1069 (5).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1586.
Data sources
Telemetry that can reveal T1586, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content
- Persona — Social Media
Threat actors using it
Tracked threats
The 30 most recent of 140 tracked threats that use T1586.
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- GepyS Banking Malware and Rust Clipboard Hijacker: Two H1 2026 Attack Chains (Gen Digital)high
- Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre…
- AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat…high
- Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident…high
- SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User Recordshigh
- Mon General Hospital (West Virginia) Notifies Patients After May 2026 Phishing Attack Compromises Employee…high
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claimshigh
- AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Thefthigh
- Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…critical
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojancritical
- Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026high
- Real-Time Credential Relay Phishing Campaign Targets Call of Duty Mobile Players via Fake CP Giveawaymedium
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Callshigh
- SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…high
- SourTrade Malvertising: ServiceWorker-Orchestrated In-Browser Assembly Builds a Unique Windows Executable…high
- Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers…critical
- ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows…medium
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Datahigh
- Upbound Group Data Theft Enables $13M in Fraudulent Acima Lease-to-Own Fraud (Q2 2026)medium
- Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggeringcritical
- AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN…medium
- ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The…medium
- Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime…medium
- SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machineshigh
- Patriot Bait Actor "bandcampro" Abuses Jailbroken Google Gemini CLI to Build and Operate a Dental Clinic…medium
- ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaignhigh
- SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…high
- Coordinated Domain Impersonation Campaign Exploits Fable 5/Mythos 5 AI Model Export-Control Ban — 117+…high
- SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer Accountshigh
Detection coverage
Threadlinqs maintains 23 detection rules mapped to T1586 (SPL 3, KQL 8, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1586.001 Social Media Accounts — 9 tracked threats
- T1586.002 Email Accounts — 32 tracked threats
- T1586.003 Cloud Accounts — 8 tracked threats