MITRE ATT&CK Technique
Resource Development T1586.001
Description

Adversaries may compromise social media accounts that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating social media profiles (i.e. [Social Media Accounts](https://attack.mitre.org/techniques/T1585/001)), adversaries may compromise existing social media accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona. A variety of methods exist for compromising social media accounts, such as gathering credentials via [Phishing for Information](https://attack.mitre.org/techniques/T1598), purchasing credentials from third-party sites, or by brute forcing credentials (ex: password reuse from breach credential dumps).(Citation: AnonHBGary) Prior to compromising social media accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation. Personas may exist on a single site or across multiple sites (ex: Facebook, LinkedIn, Twitter, etc.). Compromised social media accounts may require additional development, this could include filling out or modifying profile information, further developing social networks, or incorporating photos. Adversaries can use a compromised social media profile to create new, or hijack existing, connections to targets of interest. These connections may be direct or may include trying to connect through others.(Citation: NEWSCASTER2014)(Citation: BlackHatRobinSage) Compromised profiles may be leveraged during other phases of the adversary lifecycle, such as during Initial Access (ex: [Spearphishing via Service](https://attack.mitre.org/techniques/T1566/003)).

Supported Platforms
PRE
Created

April 29, 2026

Last Updated

April 29, 2026

STIX Data
{'created': '2020-10-01T01:18:35.535Z',
 'created_by_ref': 'identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5',
 'description': 'Adversaries may compromise social media accounts that can be '
                'used during targeting. For operations incorporating social '
                'engineering, the utilization of an online persona may be '
                'important. Rather than creating and cultivating social media '
                'profiles (i.e. [Social Media '
                'Accounts](https://attack.mitre.org/techniques/T1585/001)), '
                'adversaries may compromise existing social media accounts. '
                'Utilizing an existing persona may engender a level of trust '
                'in a potential victim if they have a relationship, or '
                'knowledge of, the compromised persona. \n'
                '\n'
                'A variety of methods exist for compromising social media '
                'accounts, such as gathering credentials via [Phishing for '
                'Information](https://attack.mitre.org/techniques/T1598), '
                'purchasing credentials from third-party sites, or by brute '
                'forcing credentials (ex: password reuse from breach '
                'credential dumps).(Citation: AnonHBGary) Prior to '
                'compromising social media accounts, adversaries may conduct '
                'Reconnaissance to inform decisions about which accounts to '
                'compromise to further their operation.\n'
                '\n'
                'Personas may exist on a single site or across multiple sites '
                '(ex: Facebook, LinkedIn, Twitter, etc.). Compromised social '
                'media accounts may require additional development, this could '
                'include filling out or modifying profile information, further '
                'developing social networks, or incorporating photos.\n'
                '\n'
                'Adversaries can use a compromised social media profile to '
                'create new, or hijack existing, connections to targets of '
                'interest. These connections may be direct or may include '
                'trying to connect through others.(Citation: '
                'NEWSCASTER2014)(Citation: BlackHatRobinSage) Compromised '
                'profiles may be leveraged during other phases of the '
                'adversary lifecycle, such as during Initial Access (ex: '
                '[Spearphishing via '
                'Service](https://attack.mitre.org/techniques/T1566/003)).',
 'external_references': [{'external_id': 'T1586.001',
                          'source_name': 'mitre-attack',
                          'url': 'https://attack.mitre.org/techniques/T1586/001'},
                         {'description': 'Bright, P. (2011, February 15). '
                                         'Anonymous speaks: the inside story '
                                         'of the HBGary hack. Retrieved March '
                                         '9, 2017.',
                          'source_name': 'AnonHBGary',
                          'url': 'https://arstechnica.com/tech-policy/2011/02/anonymous-speaks-the-inside-story-of-the-hbgary-hack/'},
                         {'description': 'Lennon, M. (2014, May 29). Iranian '
                                         'Hackers Targeted US Officials in '
                                         'Elaborate Social Media Attack '
                                         'Operation. Retrieved March 1, 2017.',
                          'source_name': 'NEWSCASTER2014',
                          'url': 'https://www.securityweek.com/iranian-hackers-targeted-us-officials-elaborate-social-media-attack-operation'},
                         {'description': 'Ryan, T. (2010). “Getting In Bed '
                                         'with Robin Sage.”. Retrieved March '
                                         '6, 2017.',
                          'source_name': 'BlackHatRobinSage',
                          'url': 'http://media.blackhat.com/bh-us-10/whitepapers/Ryan/BlackHat-USA-2010-Ryan-Getting-In-Bed-With-Robin-Sage-v1.0.pdf'}],
 'id': 'attack-pattern--274770e0-2612-4ccf-a678-ef8e7bad365d',
 'kill_chain_phases': [{'kill_chain_name': 'mitre-attack',
                        'phase_name': 'resource-development'}],
 'modified': '2025-10-24T17:48:32.696Z',
 'name': 'Social Media Accounts',
 'object_marking_refs': ['marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168'],
 'revoked': False,
 'spec_version': '2.1',
 'type': 'attack-pattern',
 'x_mitre_attack_spec_version': '3.2.0',
 'x_mitre_deprecated': False,
 'x_mitre_detection': '',
 'x_mitre_domains': ['enterprise-attack'],
 'x_mitre_is_subtechnique': True,
 'x_mitre_modified_by_ref': 'identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5',
 'x_mitre_platforms': ['PRE'],
 'x_mitre_version': '1.1'}
Quick Actions
Related Threat Actors (2)
Sandworm Team
High

Leviathan
High