T1086: T1086
Essential information
- MITRE technique ID
T1086- Confidence
- 100/100
- Revoked
- No
- Published
- 21/12/2025 00:17
- Modified
- 27/05/2026 21:40
- Author / Source
- AlienVault
Description
No description.
Marking (TLP)
TLP:CLEAR
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (10)
-
PikaBot usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LilacSquid usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Amadey usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
APT42 usesThe MITRE Corporation Confidence 100
[APT42](https://attack.mitre.org/groups/G1044) is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.(Citation: Mandiant APT42-charms) The group primarily focuses on targets in the Middle East region, but has targeted…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Nomad Leopard usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DarkGate usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
BlackCat usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Domain usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Stargazer Goblin usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (37)
-
InkBox usesFamily
-
Hijackloader usesFamily
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DarkGate usesFamily
-
PetitPotato usesFamily
-
Rclone usesFamily
-
IcedID usesFamily
-
Ande Loader usesFamily
-
LCollection usesFamily
-
Ov3r_Stealer uses
-
InkLoader usesFamily
-
XWorm usesFamily
Reports (10)
-
14 MITREs 1 Malware 5 Observables 1 APT
-
Credential Flusher Research related11 MITREs 1 Malware 8 Observables 1 APT
-
19 MITREs 4 Malwares 38 Observables 1 APT
-
20 MITREs 2 Malwares 2 Observables
-
19 MITREs 5 Malwares 13 Observables
-
7 MITREs 2 Malwares 14 Observables
-
Stargazers Ghost Network related20 MITREs 5 Malwares 37 Observables 1 APT
-
20 MITREs 4 Malwares 4 Observables 1 APT
-
12 MITREs 6 Observables
-
17 MITREs 1 Malware 15 Observables 1 APT
Vulnerabilities (CVE) (1)
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a …
- Attack vector
- Local
- Published
- 03/11/2021
- Modified
- 27/05/2026