# T1087.002 Domain Account

> As of 2026-10-05, T1087.002 (Domain Account) appears in 75 tracked threats, first reported 2026-02-06 and most recently 2026-10-01, with linked actors including Akira, Cavern Manticore, Storm-1567; it most often appears alongside T1018 (Remote System Discovery).

- **Tracked threats:** 75 (24 critical, 46 high, 5 medium)
- **First seen:** 2026-02-06
- **Last seen:** 2026-10-01
- **Threat actors:** 32
- **Detection rules:** 131 (counts only; Blue tier and above)

## Key facts

- **ID:** T1087.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Parent:** T1087
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1087/002/

## Activity timeline

T1087.002 first appeared in tracked threats on 2026-02-06 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 27 reports, and 75 of the 75 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1087.002 Domain Account is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of [T1087 Account Discovery](https://intel.threadlinqs.com/technique/T1087). Threadlinqs maps 75 of 2623 tracked threats (2.9%) to it; by severity that is 24 critical, 46 high, 5 medium.

Threats that use T1087.002 most often also use [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (51 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (41 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (39 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (35 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1087.002; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (4), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (4), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (4), [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) (3), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1087.002.

- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)

## Data sources

Telemetry that can reveal T1087.002, per MITRE ATT&CK.

- Command — Command Execution
- Group — Group Enumeration
- Network Traffic — Network Traffic Content
- Process — OS API Execution, Process Creation

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 4
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 4
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 4
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 3
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 2
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 2
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 2
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [APT10](https://intel.threadlinqs.com/actor/APT10) — 1
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1

## Tracked threats

The 30 most recent of 75 tracked threats that use T1087.002.

- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2431) — critical — 2026-09-10
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teams](https://intel.threadlinqs.com/threat/TL-2026-2302) — high — 2026-09-02
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…](https://intel.threadlinqs.com/threat/TL-2026-2265) — critical — 2026-08-31
- [TerminalFix Campaign Deploys Custom Python Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA, DLL…](https://intel.threadlinqs.com/threat/TL-2026-2260) — high — 2026-08-31
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30
- [TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers DLL Sideloading and Python Reverse-Tunnel…](https://intel.threadlinqs.com/threat/TL-2026-2237) — high — 2026-08-30
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…](https://intel.threadlinqs.com/threat/TL-2026-2201) — high — 2026-08-29
- [ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…](https://intel.threadlinqs.com/threat/TL-2026-2199) — high — 2026-08-29
- [TerminalFix Campaign: ClickFix-Style Lure Deploys Steganographic DLL Sideload and Custom Reverse Tunnel in…](https://intel.threadlinqs.com/threat/TL-2026-2198) — high — 2026-08-28
- [Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…](https://intel.threadlinqs.com/threat/TL-2026-2192) — high — 2026-08-28
- [Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting](https://intel.threadlinqs.com/threat/TL-2026-2174) — high — 2026-08-28
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay](https://intel.threadlinqs.com/threat/TL-2026-2053) — high — 2026-08-17
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…](https://intel.threadlinqs.com/threat/TL-2026-2010) — high — 2026-08-13
- [Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defender](https://intel.threadlinqs.com/threat/TL-2026-2062) — high — 2026-08-12
- [N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…](https://intel.threadlinqs.com/threat/TL-2026-1941) — high — 2026-08-08
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — critical — 2026-08-03
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…](https://intel.threadlinqs.com/threat/TL-2026-1729) — critical — 2026-07-27
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation](https://intel.threadlinqs.com/threat/TL-2026-1675) — critical — 2026-07-24
- [ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…](https://intel.threadlinqs.com/threat/TL-2026-1664) — high — 2026-07-24
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21

## Related CVEs

CVEs referenced by the tracked threats that use T1087.002, most frequent first.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556)
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-12356](https://intel.threadlinqs.com/cve/CVE-2024-12356)
- [CVE-2024-12686](https://intel.threadlinqs.com/cve/CVE-2024-12686)

## Detection coverage

Threadlinqs maintains 131 detection rules mapped to T1087.002 (SPL 36, KQL 60, Sigma 35). Rule content is available to Blue tier accounts and above; this page shows counts only.

131 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1087 Account Discovery](https://intel.threadlinqs.com/technique/T1087) — 339 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1087.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
