FORENSIA

ATT&CK · T1098

Account Manipulation

Tactics: persistence, privilege-escalation

About

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials. In order to create or manipulate accounts, the adversary must already have sufficient permissions on systems or the domain. However, account manipulation may also lead to privilege escalation where modifications grant access to additional roles, permissions, or higher-privileged Valid Accounts.

Platforms: Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

4 known groups

Software

3 malware/tools implement this

MimikatzCalistoShai-Hulud

Corpus indicators tagged with this technique

58 indicators in the corpus carry T1098.

IndicatorTypeFamilySevSrc
cve-2026-22584cve852
cve-2025-0921cve852
cve-2025-66478cve852
cve-2025-23304cve852
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
01e3dce00ea45829bd9f6a583004976ac63973a0hashcryptojacking801
b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7bsha256802
18821dbb53892d6faa14b1f063517a0302057290hashcryptojacking801
449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75ehashsupply_chain801
6894a51278ec89118276c2dd2dc36e6f9ea2790ahashphishing802
96097e0612d9575cb133021017fb1a5c68a03b60f9f3d24ebdc0e628d9034144hashsupply_chain801
bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301hashsupply_chain801
c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9eahashsupply_chain801
cf127d66124c390ca0f0b42c6385c3c8hashcryptojacking801
d0a851f0b871df60c73d2c7d3f55b031c45e4c2ehashcryptojacking801
d75cb9920d1d3d280518ddccfe4789d2hashcryptojacking801
e22d1b625ee309b60caf0252c5df7656hashcryptojacking801
febb622cd9eeb5c8860dcef4cbfd4b74hashphishing802
a14506c6fb92a5af88a6a44d273edafe10d69ee3d85c8b2a7ac458a22edf68d2sha256ransomware801
186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5dasha256ransomware801
18b8e6762afd29a09becae283083c74a19fc09db1f2c3412c42f1b0178bc122asha256ransomware801
6ba5d96e52734cbb9246bcc3decf127f780d48fa11587a1a44880c1f04404d23sha256ransomware801
a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331sha256ransomware801
febbaf5f08a8e0782ffcce8beef1f2b4e249a52bsha1ransomware781
1b9aa401457d29405c0bcf19cbf19a7028a0d214sha1ransomware781
f352cec89a56e23dae20cdd62df4d40bc7f22b5esha1ransomware781
a746da514c90f26a187a294fda7edc1bmd5ransomware761
ca8646dfc88423bb9fffda811160cebemd5ransomware761
bcee0ab10b23f5999bcdb56c0b4a631amd5ransomware761
http://sh.azurestaticprovider.net:443urlsupply_chain751

Showing the top 30 by severity of 58.