# T1021.002 SMB/Windows Admin Shares

> As of 2026-10-05, T1021.002 (SMB/Windows Admin Shares) appears in 90 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including Cavern Manticore, Qilin, The Gentlemen; it most often appears alongside T1059.001 (PowerShell).

- **Tracked threats:** 90 (32 critical, 53 high, 5 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 57
- **Detection rules:** 202 (counts only; Blue tier and above)

## Key facts

- **ID:** T1021.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Parent:** T1021
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1021/002/

## Activity timeline

T1021.002 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 23 reports, and 90 of the 90 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1021.002 SMB/Windows Admin Shares is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix, as a sub-technique of [T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021). Threadlinqs maps 90 of 2623 tracked threats (3.4%) to it; by severity that is 32 critical, 53 high, 5 medium.

Threats that use T1021.002 most often also use [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (56 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (50 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (48 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (46 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (45 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

57 tracked threat actors appear in the threats that use T1021.002; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (4), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (4), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (4), [VECT](https://intel.threadlinqs.com/actor/VECT) (4), [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (3).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1021.002.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1021.002, per MITRE ATT&CK.

- Command — Command Execution
- Logon Session — Logon Session Creation
- Network Share — Network Share Access
- Network Traffic — Network Connection Creation, Network Traffic Flow
- Process — Process Creation

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 4
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 4
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 4
- [VECT](https://intel.threadlinqs.com/actor/VECT) — 4
- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 3
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 3
- [Safepay](https://intel.threadlinqs.com/actor/Safepay) — 3
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 2
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 2

## Tracked threats

The 30 most recent of 90 tracked threats that use T1021.002.

- [Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…](https://intel.threadlinqs.com/threat/TL-2026-2868) — high — 2026-10-03
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…](https://intel.threadlinqs.com/threat/TL-2026-2352) — medium — 2026-09-06
- [Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…](https://intel.threadlinqs.com/threat/TL-2026-2283) — high — 2026-09-01
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)](https://intel.threadlinqs.com/threat/TL-2026-2212) — high — 2026-08-29
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — high — 2026-08-29
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…](https://intel.threadlinqs.com/threat/TL-2026-2201) — high — 2026-08-29
- [Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…](https://intel.threadlinqs.com/threat/TL-2026-2192) — high — 2026-08-28
- [TITAN Ransomware Claims AI Platform Analyzes 700GB of Stolen Data Per Hour](https://intel.threadlinqs.com/threat/TL-2026-2190) — high — 2026-08-28
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…](https://intel.threadlinqs.com/threat/TL-2026-2135) — high — 2026-08-24
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — critical — 2026-08-23
- [VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KB](https://intel.threadlinqs.com/threat/TL-2026-2116) — high — 2026-08-22
- [StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-2057) — high — 2026-08-18
- [CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence](https://intel.threadlinqs.com/threat/TL-2026-1825) — high — 2026-08-03
- [DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…](https://intel.threadlinqs.com/threat/TL-2026-1809) — high — 2026-08-01
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31
- [AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups](https://intel.threadlinqs.com/threat/TL-2026-1761) — medium — 2026-07-29
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…](https://intel.threadlinqs.com/threat/TL-2026-1729) — critical — 2026-07-27
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…](https://intel.threadlinqs.com/threat/TL-2026-1588) — high — 2026-07-21
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20

## Related CVEs

CVEs referenced by the tracked threats that use T1021.002, most frequent first.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291)
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)

## Detection coverage

Threadlinqs maintains 202 detection rules mapped to T1021.002 (SPL 60, KQL 79, Sigma 59, other 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

202 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021) — 364 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1021.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
