# T1586 Compromise Accounts

> As of 2026-10-05, T1586 (Compromise Accounts) appears in 140 tracked threats, first reported 2026-02-02 and most recently 2026-09-14, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1583 (Acquire Infrastructure).

- **Tracked threats:** 140 (43 critical, 72 high, 24 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-14
- **Threat actors:** 51
- **Detection rules:** 23 (counts only; Blue tier and above)

## Key facts

- **ID:** T1586
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1586/

## Activity timeline

T1586 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-14. The busiest month was 2026-07 with 54 reports, and 140 of the 140 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1586 Compromise Accounts is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 140 of 2623 tracked threats (5.3%) to it; by severity that is 43 critical, 72 high, 24 medium.

Threats that use T1586 most often also use [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (85 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (83 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (80 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (73 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (72 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

51 tracked threat actors appear in the threats that use T1586; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (19), [APT38](https://intel.threadlinqs.com/actor/APT38) (7), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (6), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (6), [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) (5).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1586.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1586, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content
- Persona — Social Media

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 19
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 7
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 6
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 6
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 5
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 4
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 3
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 3
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 3
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 3
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 3

## Tracked threats

The 30 most recent of 140 tracked threats that use T1586.

- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [GepyS Banking Malware and Rust Clipboard Hijacker: Two H1 2026 Attack Chains (Gen Digital)](https://intel.threadlinqs.com/threat/TL-2026-1934) — high — 2026-08-07
- [Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre…](https://intel.threadlinqs.com/threat/TL-2026-1889) — 2026-08-05
- [AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat…](https://intel.threadlinqs.com/threat/TL-2026-1879) — high — 2026-08-04
- [Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident…](https://intel.threadlinqs.com/threat/TL-2026-1877) — high — 2026-08-04
- [SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User Records](https://intel.threadlinqs.com/threat/TL-2026-1823) — high — 2026-08-02
- [Mon General Hospital (West Virginia) Notifies Patients After May 2026 Phishing Attack Compromises Employee…](https://intel.threadlinqs.com/threat/TL-2026-1810) — high — 2026-08-01
- [SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims](https://intel.threadlinqs.com/threat/TL-2026-1815) — high — 2026-07-29
- [AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft](https://intel.threadlinqs.com/threat/TL-2026-1811) — high — 2026-07-29
- [Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…](https://intel.threadlinqs.com/threat/TL-2026-1760) — critical — 2026-07-29
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — critical — 2026-07-28
- [Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026](https://intel.threadlinqs.com/threat/TL-2026-1737) — high — 2026-07-28
- [Real-Time Credential Relay Phishing Campaign Targets Call of Duty Mobile Players via Fake CP Giveaway](https://intel.threadlinqs.com/threat/TL-2026-1736) — medium — 2026-07-28
- [BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls](https://intel.threadlinqs.com/threat/TL-2026-1720) — high — 2026-07-27
- [SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…](https://intel.threadlinqs.com/threat/TL-2026-1703) — high — 2026-07-26
- [SourTrade Malvertising: ServiceWorker-Orchestrated In-Browser Assembly Builds a Unique Windows Executable…](https://intel.threadlinqs.com/threat/TL-2026-1696) — high — 2026-07-25
- [Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers…](https://intel.threadlinqs.com/threat/TL-2026-1681) — critical — 2026-07-25
- [ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows…](https://intel.threadlinqs.com/threat/TL-2026-1665) — medium — 2026-07-24
- [Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data](https://intel.threadlinqs.com/threat/TL-2026-1654) — high — 2026-07-23
- [Upbound Group Data Theft Enables $13M in Fraudulent Acima Lease-to-Own Fraud (Q2 2026)](https://intel.threadlinqs.com/threat/TL-2026-1634) — medium — 2026-07-22
- [Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggering](https://intel.threadlinqs.com/threat/TL-2026-1628) — critical — 2026-07-22
- [AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN…](https://intel.threadlinqs.com/threat/TL-2026-1607) — medium — 2026-07-22
- [ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The…](https://intel.threadlinqs.com/threat/TL-2026-1594) — medium — 2026-07-21
- [Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime…](https://intel.threadlinqs.com/threat/TL-2026-1578) — medium — 2026-07-20
- [SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machines](https://intel.threadlinqs.com/threat/TL-2026-1575) — high — 2026-07-20
- [Patriot Bait Actor "bandcampro" Abuses Jailbroken Google Gemini CLI to Build and Operate a Dental Clinic…](https://intel.threadlinqs.com/threat/TL-2026-1574) — medium — 2026-07-20
- [ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign](https://intel.threadlinqs.com/threat/TL-2026-1570) — high — 2026-07-20
- [SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…](https://intel.threadlinqs.com/threat/TL-2026-1532) — high — 2026-07-19
- [Coordinated Domain Impersonation Campaign Exploits Fable 5/Mythos 5 AI Model Export-Control Ban — 117+…](https://intel.threadlinqs.com/threat/TL-2026-1518) — high — 2026-07-19
- [SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer Accounts](https://intel.threadlinqs.com/threat/TL-2026-1514) — high — 2026-07-19

## Related CVEs

CVEs referenced by the tracked threats that use T1586, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-10189](https://intel.threadlinqs.com/cve/CVE-2020-10189)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-11182](https://intel.threadlinqs.com/cve/CVE-2024-11182)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-27443](https://intel.threadlinqs.com/cve/CVE-2024-27443)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)

## Detection coverage

Threadlinqs maintains 23 detection rules mapped to T1586 (SPL 3, KQL 8, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

23 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1586.001 Social Media Accounts — 9 tracked threats
- [T1586.002 Email Accounts](https://intel.threadlinqs.com/technique/T1586.002) — 32 tracked threats
- T1586.003 Cloud Accounts — 8 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1586
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
