T1134: T1134
Essential information
- MITRE technique ID
T1134- Confidence
- 100/100
- Revoked
- No
- Published
- 14/12/2017 17:46
- Modified
- 27/03/2026 01:12
- Author / Source
- The MITRE Corporation
Aliases
Access Token Manipulation
Platforms
windows
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
| mitre-attack | privilege-escalation |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (54)
-
APT 42 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at…
First seen 01/01/1970 · Last seen 16/11/5138 · -
BlackSuit usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lazarus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
All_father usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
UNC1069 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Dalbit usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DarkGate usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub…
First seen 01/01/1970 · Last seen 16/11/5138 · -
DeathGrip usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Morphing Meerkat usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (79)
-
GOREVERSE usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
HermeticWiper usesFamily The MITRE Corporation Confidence 100
[HermeticWiper](https://attack.mitre.org/software/S0697) is a data wiper that has been used since at least early 2022, primarily against Ukraine with additional activity observed in Latvia and Lithuania. Some sectors targeted…
First seen 01/01/1970 · Last seen 16/11/5138 · -
TechnoCreep usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
VPC Security usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
CloverPlus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PhantomCore usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ATOMIC usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
HideFirstLetter.dll usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
JokerSpy usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SpyC23 usesFamily The MITRE Corporation Confidence 100
[SpyC23](https://attack.mitre.org/software/S1195) is a mobile malware that has been used by [APT-C-23](https://attack.mitre.org/groups/G1028) since at least 2017. [SpyC23](https://attack.mitre.org/software/S1195) has been observed primarily targeting Android devices in the Middle East.(Citation: welivesecurity_apt-c-23)…
First seen 01/01/1970 · Last seen 16/11/5138 · -
GootBot usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (50)
-
"Ghost" Code Phishing Analysis relatedAlienVault Confidence 100 20 MITREs 1 Malware
-
AlienVault Confidence 100 18 MITREs 3 Malwares 8 IOCs 8 Observables 1 APT
-
19 MITREs 5 Observables
-
19 MITREs 2 Malwares 2 Observables 1 APT
-
Threat landscape — insurance relatedConfidence 100 199 MITREs 11 APTs
-
AlienVault Confidence 100 20 MITREs 3 IOCs 3 Observables 1 APT
-
AlienVault Confidence 100 19 MITREs 4 Malwares 4 IOCs 4 Observables
-
AlienVault Confidence 100 20 MITREs 23 IOCs 23 Observables
-
19 MITREs 2 Malwares 3 Observables
-
AlienVault Confidence 100 17 MITREs 1 Malware 1 IOC 1 Observable
-
1 CVE 19 MITREs 3 Malwares 2 Observables
-
AlienVault Confidence 100 20 MITREs 3 Malwares 2 IOCs 2 Observables 1 APT
Vulnerabilities (CVE) (59)
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file …
- Attack vector
- Local
- Published
- 24/08/2023
- Modified
- 27/05/2026
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a …
- Attack vector
- Local
- Published
- 03/11/2021
- Modified
- 27/05/2026
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a …
- Attack vector
- NETWORK
- Published
- 07/01/2026
- Modified
- 09/03/2026
Windows CSC Service Elevation of Privilege Vulnerability
- Attack vector
- LOCAL
- Published
- 09/04/2024
- Modified
- 21/12/2025
The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requirement to communicate using MQTT. It …
- Attack vector
- NETWORK
- Published
- 20/01/2023
- Modified
- 21/12/2025
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the …
- Attack vector
- Network
- Published
- 14/03/2023
- Modified
- 21/12/2025
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts …
- Attack vector
- Network
- Published
- 05/10/2023
- Modified
- 21/12/2025
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.
- Published
- 03/04/2023
- Modified
- 20/12/2025
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- Attack vector
- LOCAL
- Published
- 09/06/2021
- Modified
- 21/12/2025
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over …
- Attack vector
- Network
- Published
- 17/04/2025
- Modified
- 27/05/2026
Remote Desktop Protocol Remote Code Execution Vulnerability
- Attack vector
- NETWORK
- Published
- 11/01/2022
- Modified
- 20/12/2025
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead …
- Attack vector
- Network
- Published
- 19/08/2024
- Modified
- 21/12/2025
Course Of Action (1)
-
User Account Management mitigates