# T1003.008 /etc/passwd and /etc/shadow

> As of 2026-10-05, T1003.008 (/etc/passwd and /etc/shadow) appears in 13 tracked threats, first reported 2026-03-20 and most recently 2026-09-29; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 13 (5 critical, 8 high)
- **First seen:** 2026-03-20
- **Last seen:** 2026-09-29
- **Detection rules:** 40 (counts only; Blue tier and above)

## Key facts

- **ID:** T1003.008
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1003
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1003/008/

## Activity timeline

T1003.008 first appeared in tracked threats on 2026-03-20 and was most recently reported on 2026-09-29. The busiest month was 2026-05 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1003.008 /etc/passwd and /etc/shadow is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 8 high.

Threats that use T1003.008 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (10 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (10 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (10 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (7 threats), [T1083 File and Directory Discovery](https://intel.threadlinqs.com/technique/T1083) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1003.008.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)

## Data sources

Telemetry that can reveal T1003.008, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access

## Tracked threats

13 tracked threats use T1003.008.

- [Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses…](https://intel.threadlinqs.com/threat/TL-2026-2796) — high — 2026-09-29
- [SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local…](https://intel.threadlinqs.com/threat/TL-2026-1949) — high — 2026-08-09
- [TONTOU: Interrupt-Injection Attack Bypasses Spectre v2 (eIBRS/Safe RET) Defenses on Intel and AMD CPUs](https://intel.threadlinqs.com/threat/TL-2026-1954) — high — 2026-08-06
- [Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1105) — high — 2026-07-05
- [CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in…](https://intel.threadlinqs.com/threat/TL-2026-1067) — critical — 2026-07-02
- [CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink-Following (CWE-61) Privilege Escalation to Root on…](https://intel.threadlinqs.com/threat/TL-2026-0872) — high — 2026-06-19
- [Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host…](https://intel.threadlinqs.com/threat/TL-2026-0694) — critical — 2026-06-06
- [LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…](https://intel.threadlinqs.com/threat/TL-2026-0565) — critical — 2026-05-22
- [UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching…](https://intel.threadlinqs.com/threat/TL-2026-0564) — critical — 2026-05-22
- [Fragnesia — DirtyFrag-Family Linux Kernel LPE via XFRM ESP-in-TCP Page-Cache Corruption](https://intel.threadlinqs.com/threat/TL-2026-0510) — high — 2026-05-13
- [CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All…](https://intel.threadlinqs.com/threat/TL-2026-0486) — high — 2026-05-08
- [Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE…](https://intel.threadlinqs.com/threat/TL-2026-0483) — critical — 2026-05-08
- [CVE-2026-31979: Himmelblau Root Privilege Escalation via Symlink Attack on Kerberos Cache](https://intel.threadlinqs.com/threat/TL-2026-0258) — high — 2026-03-20

## Related CVEs

CVEs referenced by the tracked threats that use T1003.008, most frequent first.

- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-31979](https://intel.threadlinqs.com/cve/CVE-2026-31979)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-48172](https://intel.threadlinqs.com/cve/CVE-2026-48172)
- [CVE-2026-64507](https://intel.threadlinqs.com/cve/CVE-2026-64507)
- [CVE-2026-64508](https://intel.threadlinqs.com/cve/CVE-2026-64508)

## Detection coverage

Threadlinqs maintains 40 detection rules mapped to T1003.008 (SPL 10, KQL 14, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.

40 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003) — 291 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1003.008
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
