Activity timeline
T1078.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 14 reports, and 38 of the 38 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1078.003 Local Accounts is catalogued by MITRE ATT&CK under the Initial Access and Persistence and Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of T1078 Valid Accounts. Threadlinqs maps 38 of 2623 tracked threats (1.4%) to it; by severity that is 14 critical, 23 high, 1 medium.
Threats that use T1078.003 most often also use T1005 Data from Local System (22 threats), T1068 Exploitation for Privilege Escalation (21 threats), T1082 System Information Discovery (18 threats), T1190 Exploit Public-Facing Application (18 threats), T1071.001 Web Protocols (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
18 tracked threat actors appear in the threats that use T1078.003; the most frequent are Nightmare Eclipse (2), Nightmare-Eclipse (2), NightmareEclipse (2), APT38 (1), APT43 (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1078.003.
Data sources
Telemetry that can reveal T1078.003, per MITRE ATT&CK.
- Logon Session — Logon Session Creation, Logon Session Metadata
- User Account — User Account Authentication
Threat actors using it
Tracked threats
The 30 most recent of 38 tracked threats that use T1078.003.
- cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation…critical
- CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…critical
- CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Pluginhigh
- Multiple Vulnerabilities in Nozomi Guardian/CMC Before 25.4.0 on Siemens RUGGEDCOM APE1808 Devices…high
- CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…high
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injectionmedium
- Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…critical
- FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…high
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Executioncritical
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local…high
- CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligencehigh
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…high
- CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)high
- Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…high
- CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Roothigh
- GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for…critical
- CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code…high
- wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Releasedcritical
- CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…critical
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…critical
- LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…high
- LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public…high
- LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)high
- LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Servicehigh
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…high
- RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) Patchedhigh
- DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD…high
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…critical
Detection coverage
Threadlinqs maintains 106 detection rules mapped to T1078.003 (SPL 42, KQL 32, Sigma 32). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1078 Valid Accounts — 718 tracked threats at the technique level.