Activity timeline
T1078.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 13 reports, and 32 of the 32 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1078.001 Default Accounts is catalogued by MITRE ATT&CK under the Initial Access and Persistence and Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of T1078 Valid Accounts. Threadlinqs maps 32 of 2623 tracked threats (1.2%) to it; by severity that is 23 critical, 6 high, 3 medium.
Threats that use T1078.001 most often also use T1190 Exploit Public-Facing Application (27 threats), T1046 Network Service Discovery (23 threats), T1068 Exploitation for Privilege Escalation (16 threats), T1082 System Information Discovery (16 threats), T1059 Command and Scripting Interpreter (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
15 tracked threat actors appear in the threats that use T1078.001; the most frequent are Sandworm (3), Static Tundra (3), APT44 (2), FSB Center 16 (2), JADEPUFFER (2).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1078.001.
Data sources
Telemetry that can reveal T1078.001, per MITRE ATT&CK.
- Logon Session — Logon Session Creation
- User Account — User Account Authentication
Threat actors using it
Tracked threats
The 30 most recent of 32 tracked threats that use T1078.001.
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…critical
- Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…critical
- CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…critical
- CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)critical
- HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…critical
- CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russiahigh
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)critical
- Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS Vulnerabilitieshigh
- CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)critical
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransommedium
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chainhigh
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690…critical
- US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…medium
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…high
- VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and…medium
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attackcritical
- JADEPUFFER Agentic Ransomware: Autonomous LLM Agent Exploits Langflow (CVE-2025-3248) and Nacos…critical
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos…critical
- JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248)…critical
- CVE-2026-24294: NTLM Reflection Bypass via SMB on Arbitrary TCP Ports — Local Privilege Escalation to SYSTEMcritical
- Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)critical
- CVE-2026-34197 — Apache ActiveMQ Jolokia Code Injection via Spring XML Context (CISA KEV)high
- CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitationcritical
- Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication…critical
- AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55…critical
- Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and…critical
- Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…critical
Detection coverage
Threadlinqs maintains 122 detection rules mapped to T1078.001 (SPL 45, KQL 46, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1078 Valid Accounts — 718 tracked threats at the technique level.