Activity timeline
T1003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 98 reports, and 291 of the 291 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1003 OS Credential Dumping is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 291 of 2623 tracked threats (11.1%) to it; by severity that is 129 critical, 133 high, 22 medium, 2 low.
Threats that use T1003 most often also use T1059 Command and Scripting Interpreter (210 threats), T1190 Exploit Public-Facing Application (173 threats), T1071 Application Layer Protocol (166 threats), T1021 Remote Services (163 threats), T1082 System Information Discovery (161 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
105 tracked threat actors appear in the threats that use T1003; the most frequent are TeamPCP (13), Qilin (8), Sandworm (7), Static Tundra (6), Andariel (5).
Mitigations
MITRE ATT&CK lists 9 mitigations for T1003.
Data sources
Telemetry that can reveal T1003, per MITRE ATT&CK.
- Active Directory — Active Directory Object Access
- Command — Command Execution
- File — File Access, File Creation
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Process — OS API Execution, Process Access, Process Creation
- Windows Registry — Windows Registry Key Access
Threat actors using it
Tracked threats
The 30 most recent of 291 tracked threats that use T1003.
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…high
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…critical
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansashigh
- VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Thefthigh
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…high
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…critical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745…critical
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…high
- PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)high
- Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…high
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industryhigh
- ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodologyhigh
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud…high
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)high
- SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governmentscritical
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…critical
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- Ransom Busters — Rogue ransomware affiliate posing as recovery firm to intercept ransom paymentshigh
- AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…critical
- khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-Exploitationhigh
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…high
- Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…medium
Detection coverage
Threadlinqs maintains 157 detection rules mapped to T1003 (SPL 46, KQL 69, Sigma 42). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1003.001 LSASS Memory — 78 tracked threats
- T1003.002 Security Account Manager — 16 tracked threats
- T1003.003 NTDS — 17 tracked threats
- T1003.004 LSA Secrets — 6 tracked threats
- T1003.005 Cached Domain Credentials — 2 tracked threats
- T1003.006 DCSync — 13 tracked threats
- T1003.007 Proc Filesystem — 10 tracked threats
- T1003.008 /etc/passwd and /etc/shadow — 13 tracked threats