Activity timeline
T1078.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 12 reports, and 42 of the 42 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1078.002 Domain Accounts is catalogued by MITRE ATT&CK under the Initial Access and Persistence and Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of T1078 Valid Accounts. Threadlinqs maps 42 of 2623 tracked threats (1.6%) to it; by severity that is 21 critical, 18 high, 3 medium.
Threats that use T1078.002 most often also use T1021.002 SMB/Windows Admin Shares (25 threats), T1190 Exploit Public-Facing Application (25 threats), T1059.001 PowerShell (21 threats), T1490 Inhibit System Recovery (20 threats), T1003.001 LSASS Memory (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
17 tracked threat actors appear in the threats that use T1078.002; the most frequent are GhostEmperor (2), Safepay (2), UAT-9244 (2), Akira (1), DeadLock (1).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1078.002.
Data sources
Telemetry that can reveal T1078.002, per MITRE ATT&CK.
- Logon Session — Logon Session Creation, Logon Session Metadata
- User Account — User Account Authentication
Threat actors using it
Tracked threats
The 30 most recent of 42 tracked threats that use T1078.002.
- Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898…critical
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patientshigh
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…critical
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…high
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoastinghigh
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victimshigh
- Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026medium
- WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedureshigh
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…high
- CVE-2026-6516: Unauthenticated Remote Code Execution in ManageEngine ADAudit Plus (CVSS 10.0)critical
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltrationhigh
- MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals…high
- CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonationcritical
- CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine…critical
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…critical
- Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…high
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Dayscritical
- Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US Productionhigh
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…critical
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public)critical
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…high
- Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailermedium
- CVE-2026-44748: XML Signature Wrapping in SAP NetWeaver AS ABAP SAML Authentication (CVSS 9.9)critical
- FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT…critical
- Unpatched Windows search: URI Handler NTLMv2 Hash Leak via crumb=location UNC Coercion (No CVE, Microsoft…high
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…high
Detection coverage
Threadlinqs maintains 103 detection rules mapped to T1078.002 (SPL 40, KQL 32, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1078 Valid Accounts — 718 tracked threats at the technique level.