# T1003.002 Security Account Manager

> As of 2026-10-05, T1003.002 (Security Account Manager) appears in 16 tracked threats, first reported 2026-02-20 and most recently 2026-10-03, with linked actors including Nightmare Eclipse, Nightmare-Eclipse, Akira; it most often appears alongside T1036.005 (Match Legitimate Resource Name or Location).

- **Tracked threats:** 16 (1 critical, 15 high)
- **First seen:** 2026-02-20
- **Last seen:** 2026-10-03
- **Threat actors:** 8
- **Detection rules:** 56 (counts only; Blue tier and above)

## Key facts

- **ID:** T1003.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1003
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1003/002/

## Activity timeline

T1003.002 first appeared in tracked threats on 2026-02-20 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 4 reports, and 16 of the 16 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1003.002 Security Account Manager is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003). Threadlinqs maps 16 of 2623 tracked threats (0.6%) to it; by severity that is 1 critical, 15 high.

Threats that use T1003.002 most often also use [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (9 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (9 threats), [T1059.003 Windows Command Shell](https://intel.threadlinqs.com/technique/T1059.003) (9 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1003.002; the most frequent are [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (3), [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) (2), [Akira](https://intel.threadlinqs.com/actor/Akira) (1), [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (1), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1003.002.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)

## Data sources

Telemetry that can reveal T1003.002, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access, File Creation
- Windows Registry — Windows Registry Key Access

## Threat actors using it

- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 3
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) — 1
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1
- [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) — 1

## Tracked threats

16 tracked threats use T1003.002.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)](https://intel.threadlinqs.com/threat/TL-2026-2576) — high — 2026-09-19
- [FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…](https://intel.threadlinqs.com/threat/TL-2026-2330) — high — 2026-09-04
- [khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2067) — high — 2026-08-18
- [Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…](https://intel.threadlinqs.com/threat/TL-2026-1496) — high — 2026-07-18
- [Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…](https://intel.threadlinqs.com/threat/TL-2026-1448) — high — 2026-07-17
- [Spirals Ransomware: Rust-Based Double Extortion Campaign Against South Asian IT Company](https://intel.threadlinqs.com/threat/TL-2026-2399) — critical — 2026-07-16
- [LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…](https://intel.threadlinqs.com/threat/TL-2026-1373) — high — 2026-07-15
- [Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…](https://intel.threadlinqs.com/threat/TL-2026-0755) — high — 2026-06-10
- [Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)](https://intel.threadlinqs.com/threat/TL-2026-0743) — high — 2026-06-10
- [Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…](https://intel.threadlinqs.com/threat/TL-2026-0583) — high — 2026-05-25
- [Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and…](https://intel.threadlinqs.com/threat/TL-2026-0500) — high — 2026-05-12
- [SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon…](https://intel.threadlinqs.com/threat/TL-2026-0493) — high — 2026-05-11
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [Windows False File Immutability Kernel Exploit — Cloud File Sync Driver (cldflt.sys) Bypass, PoC Available…](https://intel.threadlinqs.com/threat/TL-2026-0134) — high — 2026-02-23
- [CVE-2025-29824: Windows CLFS Use-After-Free Privilege Escalation Chained with Cisco ASA Compromise and…](https://intel.threadlinqs.com/threat/TL-2026-1543) — high — 2026-02-20

## Related CVEs

CVEs referenced by the tracked threats that use T1003.002, most frequent first.

- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)

## Detection coverage

Threadlinqs maintains 56 detection rules mapped to T1003.002 (SPL 22, KQL 21, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.

56 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003) — 291 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1003.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
