Activity timeline
T1087.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 27 reports, and 75 of the 75 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1087.002 Domain Account is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of T1087 Account Discovery. Threadlinqs maps 75 of 2623 tracked threats (2.9%) to it; by severity that is 24 critical, 46 high, 5 medium.
Threats that use T1087.002 most often also use T1018 Remote System Discovery (51 threats), T1059.001 PowerShell (41 threats), T1071.001 Web Protocols (39 threats), T1190 Exploit Public-Facing Application (35 threats), T1027 Obfuscated Files or Information (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
32 tracked threat actors appear in the threats that use T1087.002; the most frequent are Akira (4), Cavern Manticore (4), Storm-1567 (4), DragonForce (3), MuddyWater (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1087.002.
Data sources
Telemetry that can reveal T1087.002, per MITRE ATT&CK.
- Command — Command Execution
- Group — Group Enumeration
- Network Traffic — Network Traffic Content
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 75 tracked threats that use T1087.002.
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devicescritical
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teamshigh
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…critical
- TerminalFix Campaign Deploys Custom Python Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA, DLL…high
- Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…high
- TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers DLL Sideloading and Python Reverse-Tunnel…high
- Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…high
- ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…high
- TerminalFix Campaign: ClickFix-Style Lure Deploys Steganographic DLL Sideload and Custom Reverse Tunnel in…high
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…high
- Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoastinghigh
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victimshigh
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relayhigh
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…high
- Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defenderhigh
- N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…high
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeovercritical
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…critical
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltrationhigh
- CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonationcritical
- ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…high
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
Detection coverage
Threadlinqs maintains 131 detection rules mapped to T1087.002 (SPL 36, KQL 60, Sigma 35). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1087 Account Discovery — 339 tracked threats at the technique level.