# T1078.003 Local Accounts

> As of 2026-10-05, T1078.003 (Local Accounts) appears in 38 tracked threats, first reported 2026-02-03 and most recently 2026-09-23, with linked actors including Nightmare Eclipse, Nightmare-Eclipse, NightmareEclipse; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 38 (14 critical, 23 high, 1 medium)
- **First seen:** 2026-02-03
- **Last seen:** 2026-09-23
- **Threat actors:** 18
- **Detection rules:** 106 (counts only; Blue tier and above)

## Key facts

- **ID:** T1078.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access, Persistence, Privilege Escalation, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1078
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1078/003/

## Activity timeline

T1078.003 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-09-23. The busiest month was 2026-07 with 14 reports, and 38 of the 38 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1078.003 Local Accounts is catalogued by MITRE ATT&CK under the Initial Access and Persistence and Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078). Threadlinqs maps 38 of 2623 tracked threats (1.4%) to it; by severity that is 14 critical, 23 high, 1 medium.

Threats that use T1078.003 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (22 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (21 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (18 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (18 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

18 tracked threat actors appear in the threats that use T1078.003; the most frequent are [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (2), [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) (2), [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [APT43](https://intel.threadlinqs.com/actor/APT43) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1078.003.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1078.003, per MITRE ATT&CK.

- Logon Session — Logon Session Creation, Logon Session Metadata
- User Account — User Account Authentication

## Threat actors using it

- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 2
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 2
- [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [DeadLock](https://intel.threadlinqs.com/actor/DeadLock) — 1
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1

## Tracked threats

The 30 most recent of 38 tracked threats that use T1078.003.

- [cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation…](https://intel.threadlinqs.com/threat/TL-2026-2636) — critical — 2026-09-23
- [CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…](https://intel.threadlinqs.com/threat/TL-2026-2542) — critical — 2026-09-16
- [CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Plugin](https://intel.threadlinqs.com/threat/TL-2026-2523) — high — 2026-09-15
- [Multiple Vulnerabilities in Nozomi Guardian/CMC Before 25.4.0 on Siemens RUGGEDCOM APE1808 Devices…](https://intel.threadlinqs.com/threat/TL-2026-2487) — high — 2026-09-13
- [CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…](https://intel.threadlinqs.com/threat/TL-2026-2479) — high — 2026-09-13
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — medium — 2026-09-13
- [Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…](https://intel.threadlinqs.com/threat/TL-2026-2340) — critical — 2026-09-05
- [FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…](https://intel.threadlinqs.com/threat/TL-2026-2330) — high — 2026-09-04
- [CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2177) — critical — 2026-08-28
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local…](https://intel.threadlinqs.com/threat/TL-2026-1949) — high — 2026-08-09
- [CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence](https://intel.threadlinqs.com/threat/TL-2026-1825) — high — 2026-08-03
- [DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…](https://intel.threadlinqs.com/threat/TL-2026-1809) — high — 2026-08-01
- [CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-1707) — high — 2026-07-26
- [Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…](https://intel.threadlinqs.com/threat/TL-2026-1643) — high — 2026-07-22
- [CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root](https://intel.threadlinqs.com/threat/TL-2026-1633) — high — 2026-07-22
- [GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for…](https://intel.threadlinqs.com/threat/TL-2026-1579) — critical — 2026-07-20
- [CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code…](https://intel.threadlinqs.com/threat/TL-2026-1507) — high — 2026-07-19
- [wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Released](https://intel.threadlinqs.com/threat/TL-2026-1465) — critical — 2026-07-18
- [CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-1464) — critical — 2026-07-17
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…](https://intel.threadlinqs.com/threat/TL-2026-1463) — critical — 2026-07-17
- [LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…](https://intel.threadlinqs.com/threat/TL-2026-1449) — high — 2026-07-17
- [LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public…](https://intel.threadlinqs.com/threat/TL-2026-1445) — high — 2026-07-17
- [LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)](https://intel.threadlinqs.com/threat/TL-2026-1414) — high — 2026-07-16
- [LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Service](https://intel.threadlinqs.com/threat/TL-2026-1351) — high — 2026-07-15
- [Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…](https://intel.threadlinqs.com/threat/TL-2026-1277) — high — 2026-07-13
- [RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) Patched](https://intel.threadlinqs.com/threat/TL-2026-1157) — high — 2026-07-10
- [DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD…](https://intel.threadlinqs.com/threat/TL-2026-0819) — high — 2026-06-16
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…](https://intel.threadlinqs.com/threat/TL-2026-0565) — critical — 2026-05-22

## Related CVEs

CVEs referenced by the tracked threats that use T1078.003, most frequent first.

- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-87886](https://intel.threadlinqs.com/cve/CVE-2026-87886)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-20817](https://intel.threadlinqs.com/cve/CVE-2026-20817)
- [CVE-2026-23760](https://intel.threadlinqs.com/cve/CVE-2026-23760)
- [CVE-2026-24423](https://intel.threadlinqs.com/cve/CVE-2026-24423)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42980](https://intel.threadlinqs.com/cve/CVE-2026-42980)
- [CVE-2026-48172](https://intel.threadlinqs.com/cve/CVE-2026-48172)
- [CVE-2026-50656](https://intel.threadlinqs.com/cve/CVE-2026-50656)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-68490](https://intel.threadlinqs.com/cve/CVE-2026-68490)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2026-6973](https://intel.threadlinqs.com/cve/CVE-2026-6973)
- [CVE-2026-76460](https://intel.threadlinqs.com/cve/CVE-2026-76460)
- [CVE-2026-8933](https://intel.threadlinqs.com/cve/CVE-2026-8933)

## Detection coverage

Threadlinqs maintains 106 detection rules mapped to T1078.003 (SPL 42, KQL 32, Sigma 32). Rule content is available to Blue tier accounts and above; this page shows counts only.

106 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) — 718 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1078.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
