# T1003.003 NTDS

> As of 2026-10-05, T1003.003 (NTDS) appears in 17 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including Akira, Rhysida, Storm-1567; it most often appears alongside T1021.001 (Remote Desktop Protocol).

- **Tracked threats:** 17 (6 critical, 9 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 7
- **Detection rules:** 39 (counts only; Blue tier and above)

## Key facts

- **ID:** T1003.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1003
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1003/003/

## Activity timeline

T1003.003 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-02 with 4 reports, and 17 of the 17 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1003.003 NTDS is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003). Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 6 critical, 9 high, 2 medium.

Threats that use T1003.003 most often also use [T1021.001 Remote Desktop Protocol](https://intel.threadlinqs.com/technique/T1021.001) (10 threats), [T1572 Protocol Tunneling](https://intel.threadlinqs.com/technique/T1572) (10 threats), [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (9 threats), [T1219 Remote Access Tools](https://intel.threadlinqs.com/technique/T1219) (9 threats), [T1003.001 LSASS Memory](https://intel.threadlinqs.com/technique/T1003.001) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1003.003; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (2), [Rhysida](https://intel.threadlinqs.com/actor/Rhysida) (2), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (2), [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) (1), [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1003.003.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)

## Data sources

Telemetry that can reveal T1003.003, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 2
- [Rhysida](https://intel.threadlinqs.com/actor/Rhysida) — 2
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 2
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 1
- [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) — 1
- [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) — 1
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 1

## Tracked threats

17 tracked threats use T1003.003.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — high — 2026-08-29
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…](https://intel.threadlinqs.com/threat/TL-2026-1729) — critical — 2026-07-27
- [Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…](https://intel.threadlinqs.com/threat/TL-2026-1496) — high — 2026-07-18
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — critical — 2026-06-29
- [Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon…](https://intel.threadlinqs.com/threat/TL-2026-0504) — high — 2026-05-12
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [QEMU Virtualization Abuse for PayoutsKing Ransomware Delivery & Evasion](https://intel.threadlinqs.com/threat/TL-2026-0379) — high — 2026-04-16
- [Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…](https://intel.threadlinqs.com/threat/TL-2026-0123) — critical — 2026-02-21
- [Microsoft NTLM Deprecation - Three-Stage Phase-Out Plan](https://intel.threadlinqs.com/threat/TL-2026-0040) — high — 2026-02-03
- [Microsoft NTLM Deprecation - Enterprise Migration Planning Required](https://intel.threadlinqs.com/threat/TL-2026-0018) — medium — 2026-02-02
- [Microsoft NTLM Phase-Out: Detection & Migration Guidance](https://intel.threadlinqs.com/threat/TL-2026-0009) — medium — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T1003.003, most frequent first.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-32161](https://intel.threadlinqs.com/cve/CVE-2026-32161)
- [CVE-2026-33109](https://intel.threadlinqs.com/cve/CVE-2026-33109)
- [CVE-2026-33844](https://intel.threadlinqs.com/cve/CVE-2026-33844)
- [CVE-2026-35421](https://intel.threadlinqs.com/cve/CVE-2026-35421)
- [CVE-2026-40358](https://intel.threadlinqs.com/cve/CVE-2026-40358)
- [CVE-2026-40361](https://intel.threadlinqs.com/cve/CVE-2026-40361)
- [CVE-2026-40363](https://intel.threadlinqs.com/cve/CVE-2026-40363)
- [CVE-2026-40364](https://intel.threadlinqs.com/cve/CVE-2026-40364)
- [CVE-2026-40365](https://intel.threadlinqs.com/cve/CVE-2026-40365)
- [CVE-2026-40366](https://intel.threadlinqs.com/cve/CVE-2026-40366)
- [CVE-2026-40367](https://intel.threadlinqs.com/cve/CVE-2026-40367)
- [CVE-2026-40402](https://intel.threadlinqs.com/cve/CVE-2026-40402)
- [CVE-2026-40403](https://intel.threadlinqs.com/cve/CVE-2026-40403)
- [CVE-2026-41089](https://intel.threadlinqs.com/cve/CVE-2026-41089)
- [CVE-2026-41096](https://intel.threadlinqs.com/cve/CVE-2026-41096)
- [CVE-2026-42831](https://intel.threadlinqs.com/cve/CVE-2026-42831)
- [CVE-2026-42898](https://intel.threadlinqs.com/cve/CVE-2026-42898)
- [CVE-2026-69525](https://intel.threadlinqs.com/cve/CVE-2026-69525)
- [CVE-2026-69730](https://intel.threadlinqs.com/cve/CVE-2026-69730)
- [CVE-2026-69819](https://intel.threadlinqs.com/cve/CVE-2026-69819)
- [CVE-2026-70352](https://intel.threadlinqs.com/cve/CVE-2026-70352)

## Detection coverage

Threadlinqs maintains 39 detection rules mapped to T1003.003 (SPL 14, KQL 17, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

39 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003) — 291 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1003.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
