Activity timeline
T1484 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 15 reports, and 30 of the 30 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1484 Domain or Tenant Policy Modification is catalogued by MITRE ATT&CK under the Privilege Escalation and Defense Impairment tactics in the Enterprise matrix. Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 17 critical, 11 high, 2 medium.
Threats that use T1484 most often also use T1003 OS Credential Dumping (24 threats), T1685 Disable or Modify Tools (23 threats), T1486 Data Encrypted for Impact (22 threats), T1078 Valid Accounts (21 threats), T1059 Command and Scripting Interpreter (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
31 tracked threat actors appear in the threats that use T1484; the most frequent are Void Manticore (4), Handala Hack (3), LockBit (3), Scattered Spider (3), Storm-2603 (3).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1484.
Data sources
Telemetry that can reveal T1484, per MITRE ATT&CK.
- Active Directory — Active Directory Object Creation, Active Directory Object Deletion, Active Directory Object Modification
- Application Log — Application Log Content
- Command — Command Execution
Threat actors using it
Tracked threats
30 tracked threats use T1484.
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCEcritical
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…high
- CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…critical
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…critical
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops…critical
- France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign…high
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)high
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demandsmedium
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164…high
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659…critical
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days…critical
- Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS…high
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege…critical
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV…medium
- CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deploymentcritical
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strikehigh
- CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by…critical
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdowncritical
- SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark Campaignhigh
- Azure Blob Storage Ransomware: Four Storage-Encryption Abuse Methods (BlackCat/ALPHV, STORM-0501)high
- Foxconn North American Factories Cyberattack — Nitrogen Ransomware Claims 8 TB / 11M+ Documents Stolen…critical
- Human-Operated Ransomware via GPO Abuse — Domain-Wide Encryption Through Group Policy Weaponizationhigh
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker…critical
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device…critical
- Warlock (Water Manaul / Storm-2603) Ransomware Campaign with BYOVD, Web Shells, and Multi-Channel Tunneling…critical
- Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attackcritical
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypasshigh
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineeringcritical
Detection coverage
Threadlinqs maintains 12 detection rules mapped to T1484 (SPL 5, KQL 4, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1484.001 Group Policy Modification — 14 tracked threats
- T1484.002 Trust Modification — 2 tracked threats