Activity timeline
T1003.008 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-05 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1003.008 /etc/passwd and /etc/shadow is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1003 OS Credential Dumping. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 8 high.
Threats that use T1003.008 most often also use T1059.004 Unix Shell (10 threats), T1068 Exploitation for Privilege Escalation (10 threats), T1082 System Information Discovery (10 threats), T1005 Data from Local System (7 threats), T1083 File and Directory Discovery (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
Mitigations
MITRE ATT&CK lists 2 mitigations for T1003.008.
Data sources
Telemetry that can reveal T1003.008, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
Tracked threats
13 tracked threats use T1003.008.
- Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses…high
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local…high
- TONTOU: Interrupt-Injection Attack Bypasses Spectre v2 (eIBRS/Safe RET) Defenses on Intel and AMD CPUshigh
- Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege…high
- CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in…critical
- CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink-Following (CWE-61) Privilege Escalation to Root on…high
- Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host…critical
- LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…critical
- UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching…critical
- Fragnesia — DirtyFrag-Family Linux Kernel LPE via XFRM ESP-in-TCP Page-Cache Corruptionhigh
- CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All…high
- Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE…critical
- CVE-2026-31979: Himmelblau Root Privilege Escalation via Symlink Attack on Kerberos Cachehigh
Detection coverage
Threadlinqs maintains 40 detection rules mapped to T1003.008 (SPL 10, KQL 14, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1003 OS Credential Dumping — 291 tracked threats at the technique level.