T1021.002 - SMB/Windows Admin Shares - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
12
occurrences
First Seen
April 22, 2026
Last Seen
July 23, 2026

T1021.002 - SMB/Windows Admin Shares is a mitre_attack tracked by ThreatCluster, appearing in 11 threat clusters built from 12 intelligence report mentions.

T1021.002 - SMB/Windows Admin Shares is a mitre_attack tracked across 11 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed April 22, 2026; most recent activity July 23, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • T1561 — attack.mitre.org · July 23, 2026
  • T1485 — attack.mitre.org · July 23, 2026
  • Russia's GRU Hackers Target Ukraine With Fake CAPTCHAs and an Unkillable Blockchain Server — Techtimes · July 21, 2026
  • Qilin exploits Palo Alto Networks GlobalProtect VPN firewalls — Feeds.Feedburner · July 21, 2026
  • Active Exploitation Alert: Iranian Cavern Manticore APT Abuses SysAid Supply Chain ... — Rescana · July 7, 2026
  • PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on ... — Gbhackers · June 30, 2026
  • PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on Windows Server — Gbhackers · June 30, 2026
  • G0050 — attack.mitre.org · June 11, 2026

Frequently asked questions

What is T1021.002 - SMB/Windows Admin Shares?

T1021.002 - SMB/Windows Admin Shares is a mitre_attack tracked by ThreatCluster, appearing in 11 threat clusters built from 12 intelligence report mentions.

Is T1021.002 - SMB/Windows Admin Shares still active?

The most recent intelligence report mentioning T1021.002 - SMB/Windows Admin Shares on ThreatCluster is dated July 23, 2026. Activity was first observed April 22, 2026, giving a tracked span from then to July 23, 2026.

What is T1021.002 - SMB/Windows Admin Shares associated with?

Across ThreatCluster reporting, T1021.002 - SMB/Windows Admin Shares most frequently co-occurs with Apt32, Apt38, Apt44, Cavern Manticore, Equation Group, among 12 tracked related entities.

What are the latest developments involving T1021.002 - SMB/Windows Admin Shares?

The most significant recent cluster is “MuddyWater Targets U.S. Entities Amid Geopolitical Tensions” (16 articles · Updated July 22, 2026). T1021.002 - SMB/Windows Admin Shares appears across 11 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1021.002 - SMB/Windows Admin Shares?

T1021.002 - SMB/Windows Admin Shares appears in 12 intelligence report mentions across 11 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown