# T1069.002 Domain Groups

> As of 2026-10-05, T1069.002 (Domain Groups) appears in 32 tracked threats, first reported 2026-02-16 and most recently 2026-09-26, with linked actors including Akira, Cavern Manticore, Storm-1567; it most often appears alongside T1087.002 (Domain Account).

- **Tracked threats:** 32 (8 critical, 19 high, 5 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-26
- **Threat actors:** 17
- **Detection rules:** 58 (counts only; Blue tier and above)

## Key facts

- **ID:** T1069.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Parent:** T1069
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1069/002/

## Activity timeline

T1069.002 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-26. The busiest month was 2026-07 with 11 reports, and 32 of the 32 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1069.002 Domain Groups is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of [T1069 Permission Groups Discovery](https://intel.threadlinqs.com/technique/T1069). Threadlinqs maps 32 of 2623 tracked threats (1.2%) to it; by severity that is 8 critical, 19 high, 5 medium.

Threats that use T1069.002 most often also use [T1087.002 Domain Account](https://intel.threadlinqs.com/technique/T1087.002) (23 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (22 threats), [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (20 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (20 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (18 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

17 tracked threat actors appear in the threats that use T1069.002; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (2), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (2), [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) (2), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (1).

## Data sources

Telemetry that can reveal T1069.002, per MITRE ATT&CK.

- Command — Command Execution
- Group — Group Enumeration
- Process — OS API Execution, Process Creation

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 2
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 2
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [APT10](https://intel.threadlinqs.com/actor/APT10) — 1
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1
- [FIN7](https://intel.threadlinqs.com/actor/FIN7) — 1
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [Nitrogen](https://intel.threadlinqs.com/actor/Nitrogen) — 1
- [REvil](https://intel.threadlinqs.com/actor/REvil) — 1

## Tracked threats

The 30 most recent of 32 tracked threats that use T1069.002.

- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- ["Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay](https://intel.threadlinqs.com/threat/TL-2026-2276) — high — 2026-09-01
- [TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…](https://intel.threadlinqs.com/threat/TL-2026-2265) — critical — 2026-08-31
- [TerminalFix Campaign Deploys Custom Python Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA, DLL…](https://intel.threadlinqs.com/threat/TL-2026-2260) — high — 2026-08-31
- [TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers DLL Sideloading and Python Reverse-Tunnel…](https://intel.threadlinqs.com/threat/TL-2026-2237) — high — 2026-08-30
- [ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…](https://intel.threadlinqs.com/threat/TL-2026-2199) — high — 2026-08-29
- [TerminalFix Campaign: ClickFix-Style Lure Deploys Steganographic DLL Sideload and Custom Reverse Tunnel in…](https://intel.threadlinqs.com/threat/TL-2026-2198) — high — 2026-08-28
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…](https://intel.threadlinqs.com/threat/TL-2026-1941) — high — 2026-08-08
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…](https://intel.threadlinqs.com/threat/TL-2026-1496) — high — 2026-07-18
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil…](https://intel.threadlinqs.com/threat/TL-2026-1446) — medium — 2026-07-17
- [UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign](https://intel.threadlinqs.com/threat/TL-2026-1413) — high — 2026-07-16
- [Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion…](https://intel.threadlinqs.com/threat/TL-2026-1166) — medium — 2026-07-10
- [AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for Active Directory Enumeration and S3…](https://intel.threadlinqs.com/threat/TL-2026-1152) — medium — 2026-07-09
- [Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…](https://intel.threadlinqs.com/threat/TL-2026-1137) — high — 2026-07-06
- [FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx…](https://intel.threadlinqs.com/threat/TL-2026-1090) — critical — 2026-07-02
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — critical — 2026-06-29
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…](https://intel.threadlinqs.com/threat/TL-2026-0583) — high — 2026-05-25
- [The Gentlemen Ransomware (RaaS) — Defense Evasion TTPs: Event Log Clearing, Defender Disable & AV Exclusions…](https://intel.threadlinqs.com/threat/TL-2026-0555) — high — 2026-05-21
- [Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and…](https://intel.threadlinqs.com/threat/TL-2026-0500) — high — 2026-05-12
- [UAT-8302 China-Nexus APT Campaign — NetDraft, CloudSorcerer v3, VSHELL/SNOWLIGHT, SNOWRUST…](https://intel.threadlinqs.com/threat/TL-2026-0462) — high — 2026-05-05
- [Malicious NuGet Packages — JIT Hooking ASP.NET Identity Exfiltration and Persistent Backdoor via Local Proxy…](https://intel.threadlinqs.com/threat/TL-2026-0137) — high — 2026-02-24
- [AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55…](https://intel.threadlinqs.com/threat/TL-2026-0131) — critical — 2026-02-22

## Related CVEs

CVEs referenced by the tracked threats that use T1069.002, most frequent first.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2024-12356](https://intel.threadlinqs.com/cve/CVE-2024-12356)
- [CVE-2024-12686](https://intel.threadlinqs.com/cve/CVE-2024-12686)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-1094](https://intel.threadlinqs.com/cve/CVE-2025-1094)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556)
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)

## Detection coverage

Threadlinqs maintains 58 detection rules mapped to T1069.002 (SPL 18, KQL 20, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.

58 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1069 Permission Groups Discovery](https://intel.threadlinqs.com/technique/T1069) — 101 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1069.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
