# T1586.002 Email Accounts

> As of 2026-10-05, T1586.002 (Email Accounts) appears in 32 tracked threats, first reported 2026-02-27 and most recently 2026-10-02, with linked actors including APT38, Cl0p, Gamaredon; it most often appears alongside T1566.002 (Spearphishing Link).

- **Tracked threats:** 32 (7 critical, 15 high, 10 medium)
- **First seen:** 2026-02-27
- **Last seen:** 2026-10-02
- **Threat actors:** 21
- **Detection rules:** 37 (counts only; Blue tier and above)

## Key facts

- **ID:** T1586.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1586
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1586/002/

## Activity timeline

T1586.002 first appeared in tracked threats on 2026-02-27 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 7 reports, and 32 of the 32 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1586.002 Email Accounts is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1586 Compromise Accounts](https://intel.threadlinqs.com/technique/T1586). Threadlinqs maps 32 of 2623 tracked threats (1.2%) to it; by severity that is 7 critical, 15 high, 10 medium.

Threats that use T1586.002 most often also use [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (20 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (19 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (14 threats), [T1684.001 Impersonation](https://intel.threadlinqs.com/technique/T1684.001) (14 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

21 tracked threat actors appear in the threats that use T1586.002; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) (2), [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) (2), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (2), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1586.002.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 2
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1

## Tracked threats

The 30 most recent of 32 tracked threats that use T1586.002.

- [Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data…](https://intel.threadlinqs.com/threat/TL-2026-2839) — high — 2026-10-02
- [Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+…](https://intel.threadlinqs.com/threat/TL-2026-2792) — medium — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2627) — medium — 2026-09-23
- [Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data](https://intel.threadlinqs.com/threat/TL-2026-2550) — high — 2026-09-17
- [Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…](https://intel.threadlinqs.com/threat/TL-2026-2548) — medium — 2026-09-17
- [Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial…](https://intel.threadlinqs.com/threat/TL-2026-2498) — high — 2026-09-14
- [Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)](https://intel.threadlinqs.com/threat/TL-2026-2432) — medium — 2026-09-10
- [Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login Flows](https://intel.threadlinqs.com/threat/TL-2026-2140) — high — 2026-08-25
- [Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access](https://intel.threadlinqs.com/threat/TL-2026-2129) — medium — 2026-08-24
- [Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry](https://intel.threadlinqs.com/threat/TL-2026-2088) — high — 2026-08-20
- [Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-2083) — critical — 2026-08-20
- [Mass Phishing and Scam Campaign Abuses 450+ Compromised Google Workspace Accounts in the Education Sector](https://intel.threadlinqs.com/threat/TL-2026-2004) — high — 2026-08-13
- [Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…](https://intel.threadlinqs.com/threat/TL-2026-1820) — medium — 2026-08-02
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggering](https://intel.threadlinqs.com/threat/TL-2026-1628) — critical — 2026-07-22
- [Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action…](https://intel.threadlinqs.com/threat/TL-2026-1611) — medium — 2026-07-22
- [700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing…](https://intel.threadlinqs.com/threat/TL-2026-1519) — medium — 2026-07-19
- [PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…](https://intel.threadlinqs.com/threat/TL-2026-1416) — high — 2026-07-16
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1161) — high — 2026-07-10
- [Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw…](https://intel.threadlinqs.com/threat/TL-2026-1216) — high — 2026-06-29
- [CISA KEV Adds CVE-2026-12569 (PTC Windchill/FlexPLM Unauthenticated RCE via Deserialization) and…](https://intel.threadlinqs.com/threat/TL-2026-1244) — critical — 2026-06-25
- [Malwarebytes Subscription Renewal Scam — Fake-Invoice / Refund-Bait Callback Phishing Campaign ("Account…](https://intel.threadlinqs.com/threat/TL-2026-0936) — medium — 2026-06-24
- ["Total Access to All Your Devices" Sextortion Email Extortion Campaign](https://intel.threadlinqs.com/threat/TL-2026-0934) — medium — 2026-06-24
- [Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle…](https://intel.threadlinqs.com/threat/TL-2026-0758) — critical — 2026-06-10
- [2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu…](https://intel.threadlinqs.com/threat/TL-2026-0578) — high — 2026-05-25
- [Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace\[.\]cloud Operation…](https://intel.threadlinqs.com/threat/TL-2026-0533) — high — 2026-05-19
- [Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) — Credential Stealer with DNS Exfiltration via…](https://intel.threadlinqs.com/threat/TL-2026-0518) — critical — 2026-05-15
- [Telnyx Python SDK PyPI Compromise — TeamPCP CanisterWorm Supply Chain Attack (telnyx 4.87.1/4.87.2)](https://intel.threadlinqs.com/threat/TL-2026-0361) — critical — 2026-04-14

## Related CVEs

CVEs referenced by the tracked threats that use T1586.002, most frequent first.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)

## Detection coverage

Threadlinqs maintains 37 detection rules mapped to T1586.002 (SPL 11, KQL 16, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

37 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1586 Compromise Accounts](https://intel.threadlinqs.com/technique/T1586) — 140 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1586.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
