FORENSIA

ATT&CK · T1136.001 · sub-technique

Local Account

Tactics: persistence

About

Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. For example, with a sufficient level of access, the Windows <code>net user /add</code> command can be used to create a local account. In Linux, the `useradd` command can be used, while on macOS systems, the <code>dscl -create</code> command can be used. Local accounts may also be added to network devices, often via common Network Device CLI commands such as <code>username</code>, to ESXi servers via `esxcli system account add`, or to Kubernetes clusters using the `kubectl` utility. Adversaries may also create new local accounts on network firewall management consoles – for example, by exploiting a vulnerable firewall management system, threat actors may be able to establish super-admin accounts that could be used to modify firewall rules and gain further access to the network. Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Platforms: Containers, ESXi, Linux, macOS, Network Devices, WindowsParent: T1136 Create AccountMITRE ATT&CK ↗

Used by actors

14 known groups

Software

15 malware/tools implement this

CarbanakNetMis-TypeS-TypeFlamePupyCalistoEmpireServHelperHiddenWaspZxShellGoldenSpyHildegardSMOKEDHAMDarkGate

Corpus indicators tagged with this technique

74 indicators in the corpus carry T1136.001.

IndicatorTypeFamilySevSrc
cve-2026-4368cveransomware851
eb083365dc70d0294e8c4f55a2e78be0edb0f3497f2a06a70c9f474dafab48d8sha256ransomware801
83a7e51f3787ac5a8a9884edd0a58ddbef380969aa6529d282a461a1a614a892sha256ransomware801
686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4sha256ransomware801
c4fcae3847946173bf0b3cedf5d97a9e3d18090023842f942ba544fa7fda180dsha256ransomware801
c84739655ce1af0a0269138263d47567418f69e0f75e249f8e23bc21802209e2sha256ransomware801
0f9574dc38e5c34a31153f0bcc603c6ec29cb3bf65c3d25380dbe86d42573141sha256ransomware801
b5d598b00cc3a28cabc5812d9f762819334614bae452db4e7f23eefe7b081556sha256ransomware801
84b9a9a1668145df04faa3d0e118e2f0acbebd3d9d260baf3a355b44c815c22dsha256ransomware801
862a3ca7e944ccf0ff3a6d556b34faade4b68343015c35a014a43725ac14a2a1sha256ransomware801
7f0d49b11d0a3697685622ce510c570199bf2dc76515b3f9a6b6735de8c9134bsha256ransomware801
4cab935d0ec400059a3fcdc95b6623efdd51a61dff401fba8d5da244cc2de649sha256ransomware801
e25c56bd13eff7280e493bf58501c47891fe63bfsha1ransomware781
d4f8f562b4a109cccbc0dbdf28bc6d033d7891fbsha1781
32d0c3300825b0bb991c4a8f1e6244f0ad2da989sha1781
11a42ef076686cb27ba2c8845301943652a5aadcsha1781
9d94e2a15b75e1ef4487429ac71fc13e186c4a2dsha1ransomware781
f61e3a643f2417e1a1ab2c83bbdbfc8a7cb96756sha1781
ff8d2afd9d7f0a828592fee34ca55d1a3542f7edsha1781
2f3d86e77248b23ef93b7b8c2a9915b2eace5d46sha1781
c0e178d26e1e67985a9c67e649d71d54642e0eedsha1781
72cab50156ba4e2d5f4de97f672d4635e98ddaccsha1781
09002d4668a778853e8da5c488c6e421c0628357sha1781
b4101027bf2f1261402bf6318c6eb016ce249037sha1781
7493c316df2727dd19ef14593fcc014bdb2a0d4bsha1781
87867ad29e621bf9ebf57e1757f75090842458besha1781
38d744543b2051e6f749af171b5ef8d6df8aac7bsha1781
5f3f99b14243404c7cf57b40bb101244cce394bfsha1781
f89ad7e92c7de6945ce0878e470e388bmd5761
95b318d953fd939f284efe2be78fe95bmd5761

Showing the top 30 by severity of 74.