Activity timeline
T1087.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 18 reports, and 30 of the 30 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1087.001 Local Account is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of T1087 Account Discovery. Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 9 critical, 19 high, 2 medium.
Threats that use T1087.001 most often also use T1071.001 Web Protocols (20 threats), T1005 Data from Local System (19 threats), T1082 System Information Discovery (19 threats), T1190 Exploit Public-Facing Application (14 threats), T1036.005 Match Legitimate Resource Name or Location (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
23 tracked threat actors appear in the threats that use T1087.001; the most frequent are APT38 (2), Nightmare Eclipse (2), Nightmare-Eclipse (2), Sapphire Sleet (2), Stardust Chollima (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1087.001.
Data sources
Telemetry that can reveal T1087.001, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Group — Group Enumeration
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
30 tracked threats use T1087.001.
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligencehigh
- Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Commandmedium
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demandsmedium
- CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password…high
- CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code…high
- LegacyHive: Public PoC for Unpatched Windows User Profile Service (ProfSvc) Arbitrary Hive Load Elevation of…high
- CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…critical
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…critical
- Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…high
- LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public…high
- LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)high
- UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaignhigh
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoorhigh
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…high
- SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operationshigh
- ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector…high
- CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in…critical
- Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprintinghigh
- CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap…critical
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)critical
- Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packagescritical
- Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973…high
- cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEVcritical
- UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…high
- CRESCENTHARVEST — Iranian IRGC-Aligned Cyberespionage Campaign Targeting Protestors & Dissidents via DLL…high
- CSVDE.exe LOLBIN for Active Directory Reconnaissance — FIN7 + APT10/menuPass Documented Usage, Bulk LDAP…high
- SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub…critical
Detection coverage
Threadlinqs maintains 40 detection rules mapped to T1087.001 (SPL 13, KQL 16, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1087 Account Discovery — 339 tracked threats at the technique level.