Activity timeline
T1003.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-02 with 4 reports, and 17 of the 17 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1003.003 NTDS is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1003 OS Credential Dumping. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 6 critical, 9 high, 2 medium.
Threats that use T1003.003 most often also use T1021.001 Remote Desktop Protocol (10 threats), T1572 Protocol Tunneling (10 threats), T1018 Remote System Discovery (9 threats), T1219 Remote Access Tools (9 threats), T1003.001 LSASS Memory (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1003.003; the most frequent are Akira (2), Rhysida (2), Storm-1567 (2), PayoutsKing (1), UNC6201 (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1003.003.
Data sources
Telemetry that can reveal T1003.003, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
Threat actors using it
Tracked threats
17 tracked threats use T1003.003.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Electionhigh
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Thefthigh
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…critical
- Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…high
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)critical
- Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon…high
- UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…high
- QEMU Virtualization Abuse for PayoutsKing Ransomware Delivery & Evasionhigh
- Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…critical
- Microsoft NTLM Deprecation - Three-Stage Phase-Out Planhigh
- Microsoft NTLM Deprecation - Enterprise Migration Planning Requiredmedium
- Microsoft NTLM Phase-Out: Detection & Migration Guidancemedium
Detection coverage
Threadlinqs maintains 39 detection rules mapped to T1003.003 (SPL 14, KQL 17, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1003 OS Credential Dumping — 291 tracked threats at the technique level.