T1098 - Account Manipulation - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
February 12, 2026
Last Seen
June 7, 2026

T1098 - Account Manipulation is a mitre_attack tracked by ThreatCluster, appearing in 9 threat clusters built from 9 intelligence report mentions.

T1098 - Account Manipulation is a mitre_attack tracked across 9 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed February 12, 2026; most recent activity June 7, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Miasma Worm Supply Chain Attack: 73 Microsoft GitHub Repositories Compromised via AI ... — Rescana · June 7, 2026
  • T1098: Account Manipulation — aws-samples.github.io · May 19, 2026
  • Ongoing exploitation of Cisco Catalyst SD — Blog.Talosintelligence · May 14, 2026
  • New software supply chain attack uses sleeper packages for credential theft and CI tampering — Scworld · May 2, 2026
  • What the March 2026 Threat Technique Catalog update means for your AWS environment — Aws.Amazon · April 28, 2026
  • Friday's eth.limo Hijack Caused by Social Engineering on EasyDNS — Cointelegraph · April 20, 2026
  • Europol Dismantles Tycoon 2FA: Inside the Takedown of a 64,000-Attack Phishing-as — Rescana · March 5, 2026
  • Cyber Advisory: Increased Cyber Risk Amid U.S.–Israel–Iran Escalation — Sophos · March 1, 2026

Frequently asked questions

What is T1098 - Account Manipulation?

T1098 - Account Manipulation is a mitre_attack tracked by ThreatCluster, appearing in 9 threat clusters built from 9 intelligence report mentions.

Is T1098 - Account Manipulation still active?

The most recent intelligence report mentioning T1098 - Account Manipulation on ThreatCluster is dated June 7, 2026. Activity was first observed February 12, 2026, giving a tracked span from then to June 7, 2026.

What is T1098 - Account Manipulation associated with?

Across ThreatCluster reporting, T1098 - Account Manipulation most frequently co-occurs with Storm-1747, TeamPCP, Malware, Phishing, Privilege Escalation, among 12 tracked related entities.

What are the latest developments involving T1098 - Account Manipulation?

The most significant recent cluster is “Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems” (131 articles · Updated May 14, 2026). T1098 - Account Manipulation appears across 9 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1098 - Account Manipulation?

T1098 - Account Manipulation appears in 9 intelligence report mentions across 9 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown