Activity timeline
T1003.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 3 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1003.006 DCSync is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1003 OS Credential Dumping. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 8 high.
Threats that use T1003.006 most often also use T1018 Remote System Discovery (8 threats), T1021.001 Remote Desktop Protocol (8 threats), T1087.002 Domain Account (7 threats), T1053.005 Scheduled Task (6 threats), T1059.001 PowerShell (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1003.006; the most frequent are Scattered Spider (2), ALPHV (1), Qilin (1), SHADOW-EARTH-053 (1), STORM-0501 (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1003.006.
Data sources
Telemetry that can reveal T1003.006, per MITRE ATT&CK.
- Active Directory — Active Directory Object Access
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
13 tracked threats use T1003.006.
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…critical
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…high
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidentshigh
- CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonationcritical
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattackhigh
- UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting…high
- Four Methods for Azure Blob Storage Ransomware: Client-Side Bulk Encryption, CPK, Encryption Scope, and CMK…high
- SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon…high
- Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXicritical
- SolarWinds Web Help Desk Pre-Auth RCE Chain (CVE-2025-40552, CVE-2025-40553, CVE-2025-40554)critical
- AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55…critical
Detection coverage
Threadlinqs maintains 33 detection rules mapped to T1003.006 (SPL 13, KQL 16, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1003 OS Credential Dumping — 291 tracked threats at the technique level.