# T1087.001 Local Account

> As of 2026-10-05, T1087.001 (Local Account) appears in 30 tracked threats, first reported 2026-02-05 and most recently 2026-09-27, with linked actors including APT38, Nightmare Eclipse, Nightmare-Eclipse; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 30 (9 critical, 19 high, 2 medium)
- **First seen:** 2026-02-05
- **Last seen:** 2026-09-27
- **Threat actors:** 23
- **Detection rules:** 40 (counts only; Blue tier and above)

## Key facts

- **ID:** T1087.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Parent:** T1087
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1087/001/

## Activity timeline

T1087.001 first appeared in tracked threats on 2026-02-05 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 18 reports, and 30 of the 30 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1087.001 Local Account is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of [T1087 Account Discovery](https://intel.threadlinqs.com/technique/T1087). Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 9 critical, 19 high, 2 medium.

Threats that use T1087.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (20 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (19 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (19 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (14 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

23 tracked threat actors appear in the threats that use T1087.001; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (2), [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) (2), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (2), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1087.001.

- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)

## Data sources

Telemetry that can reveal T1087.001, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Group — Group Enumeration
- Process — OS API Execution, Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 2
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [APT10](https://intel.threadlinqs.com/actor/APT10) — 1
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [DriveSurge](https://intel.threadlinqs.com/actor/DriveSurge) — 1

## Tracked threats

30 tracked threats use T1087.001.

- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence](https://intel.threadlinqs.com/threat/TL-2026-1825) — high — 2026-08-03
- [Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Command](https://intel.threadlinqs.com/threat/TL-2026-1813) — medium — 2026-08-02
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password…](https://intel.threadlinqs.com/threat/TL-2026-1568) — high — 2026-07-20
- [CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code…](https://intel.threadlinqs.com/threat/TL-2026-1507) — high — 2026-07-19
- [LegacyHive: Public PoC for Unpatched Windows User Profile Service (ProfSvc) Arbitrary Hive Load Elevation of…](https://intel.threadlinqs.com/threat/TL-2026-1502) — high — 2026-07-18
- [CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-1464) — critical — 2026-07-17
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…](https://intel.threadlinqs.com/threat/TL-2026-1463) — critical — 2026-07-17
- [Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…](https://intel.threadlinqs.com/threat/TL-2026-1448) — high — 2026-07-17
- [LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public…](https://intel.threadlinqs.com/threat/TL-2026-1445) — high — 2026-07-17
- [LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)](https://intel.threadlinqs.com/threat/TL-2026-1414) — high — 2026-07-16
- [UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign](https://intel.threadlinqs.com/threat/TL-2026-1413) — high — 2026-07-16
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…](https://intel.threadlinqs.com/threat/TL-2026-1373) — high — 2026-07-15
- [SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1227) — high — 2026-07-11
- [ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector…](https://intel.threadlinqs.com/threat/TL-2026-1127) — high — 2026-07-05
- [CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in…](https://intel.threadlinqs.com/threat/TL-2026-1067) — critical — 2026-07-02
- [Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting](https://intel.threadlinqs.com/threat/TL-2026-1126) — high — 2026-07-01
- [CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap…](https://intel.threadlinqs.com/threat/TL-2026-1045) — critical — 2026-07-01
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — critical — 2026-06-29
- [Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-0979) — critical — 2026-06-12
- [Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973…](https://intel.threadlinqs.com/threat/TL-2026-0477) — high — 2026-05-07
- [cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-0440) — critical — 2026-04-30
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [CRESCENTHARVEST — Iranian IRGC-Aligned Cyberespionage Campaign Targeting Protestors & Dissidents via DLL…](https://intel.threadlinqs.com/threat/TL-2026-0159) — high — 2026-02-28
- [CSVDE.exe LOLBIN for Active Directory Reconnaissance — FIN7 + APT10/menuPass Documented Usage, Bulk LDAP…](https://intel.threadlinqs.com/threat/TL-2026-0113) — high — 2026-02-16
- [SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub…](https://intel.threadlinqs.com/threat/TL-2026-0103) — critical — 2026-02-05

## Related CVEs

CVEs referenced by the tracked threats that use T1087.001, most frequent first.

- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2026-23760](https://intel.threadlinqs.com/cve/CVE-2026-23760)
- [CVE-2026-24423](https://intel.threadlinqs.com/cve/CVE-2026-24423)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-57309](https://intel.threadlinqs.com/cve/CVE-2026-57309)
- [CVE-2026-57310](https://intel.threadlinqs.com/cve/CVE-2026-57310)
- [CVE-2026-57311](https://intel.threadlinqs.com/cve/CVE-2026-57311)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2026-6973](https://intel.threadlinqs.com/cve/CVE-2026-6973)

## Detection coverage

Threadlinqs maintains 40 detection rules mapped to T1087.001 (SPL 13, KQL 16, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

40 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1087 Account Discovery](https://intel.threadlinqs.com/technique/T1087) — 339 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1087.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
