# T1078.001 Default Accounts

> As of 2026-10-05, T1078.001 (Default Accounts) appears in 32 tracked threats, first reported 2026-02-02 and most recently 2026-10-02, with linked actors including Sandworm, Static Tundra, APT44; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 32 (23 critical, 6 high, 3 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-02
- **Threat actors:** 15
- **Detection rules:** 122 (counts only; Blue tier and above)

## Key facts

- **ID:** T1078.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access, Persistence, Privilege Escalation, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1078
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1078/001/

## Activity timeline

T1078.001 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 13 reports, and 32 of the 32 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1078.001 Default Accounts is catalogued by MITRE ATT&CK under the Initial Access and Persistence and Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078). Threadlinqs maps 32 of 2623 tracked threats (1.2%) to it; by severity that is 23 critical, 6 high, 3 medium.

Threats that use T1078.001 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (27 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (23 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (16 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (16 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

15 tracked threat actors appear in the threats that use T1078.001; the most frequent are [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (3), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (3), [APT44](https://intel.threadlinqs.com/actor/APT44) (2), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (2), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) (2).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1078.001.

- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1078.001, per MITRE ATT&CK.

- Logon Session — Logon Session Creation
- User Account — User Account Authentication

## Threat actors using it

- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 3
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 3
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 2
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 2
- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Everest](https://intel.threadlinqs.com/actor/Everest) — 1
- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 1

## Tracked threats

The 30 most recent of 32 tracked threats that use T1078.001.

- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…](https://intel.threadlinqs.com/threat/TL-2026-2851) — critical — 2026-10-02
- [Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…](https://intel.threadlinqs.com/threat/TL-2026-2611) — critical — 2026-09-21
- [CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…](https://intel.threadlinqs.com/threat/TL-2026-2542) — critical — 2026-09-16
- [CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2354) — critical — 2026-09-06
- [HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…](https://intel.threadlinqs.com/threat/TL-2026-2314) — critical — 2026-09-03
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1984) — critical — 2026-08-11
- [Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS Vulnerabilities](https://intel.threadlinqs.com/threat/TL-2026-1928) — high — 2026-08-07
- [CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)](https://intel.threadlinqs.com/threat/TL-2026-1799) — critical — 2026-07-31
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom](https://intel.threadlinqs.com/threat/TL-2026-1642) — medium — 2026-07-22
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — high — 2026-07-15
- [SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690…](https://intel.threadlinqs.com/threat/TL-2026-1302) — critical — 2026-07-14
- [US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…](https://intel.threadlinqs.com/threat/TL-2026-1290) — medium — 2026-07-14
- [FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…](https://intel.threadlinqs.com/threat/TL-2026-1283) — high — 2026-07-13
- [VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and…](https://intel.threadlinqs.com/threat/TL-2026-1261) — medium — 2026-07-13
- [JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack](https://intel.threadlinqs.com/threat/TL-2026-1117) — critical — 2026-07-05
- [JADEPUFFER Agentic Ransomware: Autonomous LLM Agent Exploits Langflow (CVE-2025-3248) and Nacos…](https://intel.threadlinqs.com/threat/TL-2026-1102) — critical — 2026-07-04
- [JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos…](https://intel.threadlinqs.com/threat/TL-2026-1083) — critical — 2026-07-02
- [JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248)…](https://intel.threadlinqs.com/threat/TL-2026-1044) — critical — 2026-07-01
- [CVE-2026-24294: NTLM Reflection Bypass via SMB on Arbitrary TCP Ports — Local Privilege Escalation to SYSTEM](https://intel.threadlinqs.com/threat/TL-2026-1007) — critical — 2026-06-30
- [Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-0800) — critical — 2026-06-15
- [CVE-2026-34197 — Apache ActiveMQ Jolokia Code Injection via Spring XML Context (CISA KEV)](https://intel.threadlinqs.com/threat/TL-2026-0386) — high — 2026-04-17
- [CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0166) — critical — 2026-03-02
- [Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication…](https://intel.threadlinqs.com/threat/TL-2026-0145) — critical — 2026-02-26
- [AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55…](https://intel.threadlinqs.com/threat/TL-2026-0131) — critical — 2026-02-22
- [Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and…](https://intel.threadlinqs.com/threat/TL-2026-0125) — critical — 2026-02-21
- [Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…](https://intel.threadlinqs.com/threat/TL-2026-0123) — critical — 2026-02-21

## Related CVEs

CVEs referenced by the tracked threats that use T1078.001, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2011-2523](https://intel.threadlinqs.com/cve/CVE-2011-2523)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2019-12108](https://intel.threadlinqs.com/cve/CVE-2019-12108)
- [CVE-2019-12109](https://intel.threadlinqs.com/cve/CVE-2019-12109)
- [CVE-2019-12110](https://intel.threadlinqs.com/cve/CVE-2019-12110)
- [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2020-28951](https://intel.threadlinqs.com/cve/CVE-2020-28951)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-67649](https://intel.threadlinqs.com/cve/CVE-2025-67649)
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-24294](https://intel.threadlinqs.com/cve/CVE-2026-24294)
- [CVE-2026-27690](https://intel.threadlinqs.com/cve/CVE-2026-27690)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)

## Detection coverage

Threadlinqs maintains 122 detection rules mapped to T1078.001 (SPL 45, KQL 46, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.

122 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) — 718 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1078.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
