# T1484.001 Group Policy Modification

> As of 2026-10-05, T1484.001 (Group Policy Modification) appears in 14 tracked threats, first reported 2026-02-02 and most recently 2026-10-01, with linked actors including Qilin, Storm-2603, The Gentlemen; it most often appears alongside T1685 (Disable or Modify Tools).

- **Tracked threats:** 14 (5 critical, 7 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-01
- **Threat actors:** 6
- **Detection rules:** 37 (counts only; Blue tier and above)

## Key facts

- **ID:** T1484.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation, Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1484
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1484/001/

## Activity timeline

T1484.001 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 4 reports, and 14 of the 14 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1484.001 Group Policy Modification is catalogued by MITRE ATT&CK under the Privilege Escalation and Defense Impairment tactics in the Enterprise matrix, as a sub-technique of [T1484 Domain or Tenant Policy Modification](https://intel.threadlinqs.com/technique/T1484). Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 7 high, 2 medium.

Threats that use T1484.001 most often also use [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (11 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (10 threats), [T1003.001 LSASS Memory](https://intel.threadlinqs.com/technique/T1003.001) (9 threats), [T1021.002 SMB/Windows Admin Shares](https://intel.threadlinqs.com/technique/T1021.002) (9 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1484.001; the most frequent are [Qilin](https://intel.threadlinqs.com/actor/Qilin) (2), [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) (2), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (2), [Akira](https://intel.threadlinqs.com/actor/Akira) (1), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1484.001.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1484.001, per MITRE ATT&CK.

- Active Directory — Active Directory Object Creation, Active Directory Object Deletion, Active Directory Object Modification
- Command — Command Execution

## Threat actors using it

- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 2
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 2
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 1
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1

## Tracked threats

14 tracked threats use T1484.001.

- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions…](https://intel.threadlinqs.com/threat/TL-2026-2828) — medium — 2026-10-01
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…](https://intel.threadlinqs.com/threat/TL-2026-2317) — high — 2026-09-03
- [Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…](https://intel.threadlinqs.com/threat/TL-2026-2192) — high — 2026-08-28
- ["Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)](https://intel.threadlinqs.com/threat/TL-2026-2039) — medium — 2026-08-17
- [CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-1434) — critical — 2026-07-17
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…](https://intel.threadlinqs.com/threat/TL-2026-1332) — high — 2026-07-14
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1061) — high — 2026-07-02
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and…](https://intel.threadlinqs.com/threat/TL-2026-0498) — critical — 2026-05-12
- [Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline Operator Conpet — 4,000km Critical Infrastructure, ~1TB…](https://intel.threadlinqs.com/threat/TL-2026-0096) — critical — 2026-02-05
- [BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest…](https://intel.threadlinqs.com/threat/TL-2026-0097) — high — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T1484.001, most frequent first.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-49704](https://intel.threadlinqs.com/cve/CVE-2025-49704)
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2025-2479](https://intel.threadlinqs.com/cve/CVE-2025-2479)
- [CVE-2025-24799](https://intel.threadlinqs.com/cve/CVE-2025-24799)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2026-23670](https://intel.threadlinqs.com/cve/CVE-2026-23670)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)

## Detection coverage

Threadlinqs maintains 37 detection rules mapped to T1484.001 (SPL 8, KQL 17, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

37 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1484 Domain or Tenant Policy Modification](https://intel.threadlinqs.com/technique/T1484) — 30 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1484.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
