# T1078.002 Domain Accounts

> As of 2026-10-05, T1078.002 (Domain Accounts) appears in 42 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including GhostEmperor, Safepay, UAT-9244; it most often appears alongside T1021.002 (SMB/Windows Admin Shares).

- **Tracked threats:** 42 (21 critical, 18 high, 3 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 17
- **Detection rules:** 103 (counts only; Blue tier and above)

## Key facts

- **ID:** T1078.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access, Persistence, Privilege Escalation, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1078
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1078/002/

## Activity timeline

T1078.002 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 12 reports, and 42 of the 42 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1078.002 Domain Accounts is catalogued by MITRE ATT&CK under the Initial Access and Persistence and Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078). Threadlinqs maps 42 of 2623 tracked threats (1.6%) to it; by severity that is 21 critical, 18 high, 3 medium.

Threats that use T1078.002 most often also use [T1021.002 SMB/Windows Admin Shares](https://intel.threadlinqs.com/technique/T1021.002) (25 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (25 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (21 threats), [T1490 Inhibit System Recovery](https://intel.threadlinqs.com/technique/T1490) (20 threats), [T1003.001 LSASS Memory](https://intel.threadlinqs.com/technique/T1003.001) (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

17 tracked threat actors appear in the threats that use T1078.002; the most frequent are [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (2), [Safepay](https://intel.threadlinqs.com/actor/Safepay) (2), [UAT-9244](https://intel.threadlinqs.com/actor/UAT-9244) (2), [Akira](https://intel.threadlinqs.com/actor/Akira) (1), [DeadLock](https://intel.threadlinqs.com/actor/DeadLock) (1).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1078.002.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1078.002, per MITRE ATT&CK.

- Logon Session — Logon Session Creation, Logon Session Metadata
- User Account — User Account Authentication

## Threat actors using it

- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 2
- [Safepay](https://intel.threadlinqs.com/actor/Safepay) — 2
- [UAT-9244](https://intel.threadlinqs.com/actor/UAT-9244) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [DeadLock](https://intel.threadlinqs.com/actor/DeadLock) — 1
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 1
- [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) — 1
- [Interlock](https://intel.threadlinqs.com/actor/Interlock) — 1
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 1
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 1
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1

## Tracked threats

The 30 most recent of 42 tracked threats that use T1078.002.

- [Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898…](https://intel.threadlinqs.com/threat/TL-2026-2854) — critical — 2026-10-03
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients](https://intel.threadlinqs.com/threat/TL-2026-2328) — high — 2026-09-04
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01
- [Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…](https://intel.threadlinqs.com/threat/TL-2026-2192) — high — 2026-08-28
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting](https://intel.threadlinqs.com/threat/TL-2026-2174) — high — 2026-08-28
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026](https://intel.threadlinqs.com/threat/TL-2026-2078) — medium — 2026-08-20
- [WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedures](https://intel.threadlinqs.com/threat/TL-2026-1966) — high — 2026-08-10
- [DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…](https://intel.threadlinqs.com/threat/TL-2026-1809) — high — 2026-08-01
- [CVE-2026-6516: Unauthenticated Remote Code Execution in ManageEngine ADAudit Plus (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1756) — critical — 2026-07-29
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals…](https://intel.threadlinqs.com/threat/TL-2026-1716) — high — 2026-07-27
- [CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation](https://intel.threadlinqs.com/threat/TL-2026-1675) — critical — 2026-07-24
- [CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine…](https://intel.threadlinqs.com/threat/TL-2026-1627) — critical — 2026-07-22
- [SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1462) — critical — 2026-07-17
- [Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…](https://intel.threadlinqs.com/threat/TL-2026-1448) — high — 2026-07-17
- [July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days](https://intel.threadlinqs.com/threat/TL-2026-1437) — critical — 2026-07-17
- [Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US Production](https://intel.threadlinqs.com/threat/TL-2026-1427) — high — 2026-07-16
- [SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…](https://intel.threadlinqs.com/threat/TL-2026-1390) — critical — 2026-07-15
- [CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public)](https://intel.threadlinqs.com/threat/TL-2026-1341) — critical — 2026-07-14
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…](https://intel.threadlinqs.com/threat/TL-2026-0882) — high — 2026-06-19
- [Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer](https://intel.threadlinqs.com/threat/TL-2026-1245) — medium — 2026-06-15
- [CVE-2026-44748: XML Signature Wrapping in SAP NetWeaver AS ABAP SAML Authentication (CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-0762) — critical — 2026-06-10
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT…](https://intel.threadlinqs.com/threat/TL-2026-0749) — critical — 2026-06-10
- [Unpatched Windows search: URI Handler NTLMv2 Hash Leak via crumb=location UNC Coercion (No CVE, Microsoft…](https://intel.threadlinqs.com/threat/TL-2026-0673) — high — 2026-06-03
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…](https://intel.threadlinqs.com/threat/TL-2026-0596) — high — 2026-05-26

## Related CVEs

CVEs referenced by the tracked threats that use T1078.002, most frequent first.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-12356](https://intel.threadlinqs.com/cve/CVE-2024-12356)
- [CVE-2024-12686](https://intel.threadlinqs.com/cve/CVE-2024-12686)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)

## Detection coverage

Threadlinqs maintains 103 detection rules mapped to T1078.002 (SPL 40, KQL 32, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.

103 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) — 718 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1078.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
