Activity timeline
T1003.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 4 reports, and 16 of the 16 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1003.002 Security Account Manager is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1003 OS Credential Dumping. Threadlinqs maps 16 of 2623 tracked threats (0.6%) to it; by severity that is 1 critical, 15 high.
Threats that use T1003.002 most often also use T1036.005 Match Legitimate Resource Name or Location (9 threats), T1059.001 PowerShell (9 threats), T1059.003 Windows Command Shell (9 threats), T1071.001 Web Protocols (9 threats), T1190 Exploit Public-Facing Application (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1003.002; the most frequent are Nightmare Eclipse (3), Nightmare-Eclipse (2), Akira (1), Chaotic Eclipse (1), MuddyWater (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1003.002.
Data sources
Telemetry that can reveal T1003.002, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access, File Creation
- Windows Registry — Windows Registry Key Access
Threat actors using it
Tracked threats
16 tracked threats use T1003.002.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)high
- FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…high
- khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-Exploitationhigh
- Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…high
- Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…high
- Spirals Ransomware: Rust-Based Double Extortion Campaign Against South Asian IT Companycritical
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…high
- Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…high
- Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)high
- Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…high
- Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and…high
- SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon…high
- UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…high
- Windows False File Immutability Kernel Exploit — Cloud File Sync Driver (cldflt.sys) Bypass, PoC Available…high
- CVE-2025-29824: Windows CLFS Use-After-Free Privilege Escalation Chained with Cisco ASA Compromise and…high
Detection coverage
Threadlinqs maintains 56 detection rules mapped to T1003.002 (SPL 22, KQL 21, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1003 OS Credential Dumping — 291 tracked threats at the technique level.