T1021.002 - SMB/Windows Admin Shares is a mitre_attack tracked by ThreatCluster, appearing in 11 threat clusters built from 12 intelligence report mentions.
T1021.002 - SMB/Windows Admin Shares is a mitre_attack tracked across 11 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed April 22, 2026; most recent activity July 23, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
Researchers at SentinelOne have uncovered a malware framework named fast16, which dates back to 2005 and predates the infamous Stuxnet worm by five years. Fast16 is designed to subtly corrupt high-precision mathematical…
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
A proof-of-concept (PoC) exploit has been released for a NTLM reflection bypass vulnerability, tracked as CVE-2026-24294, which allows attackers to gain SYSTEM-level access on Windows Server 2025. This vulnerability…
The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect VPN software. This flaw allows attackers to bypass security…
Cyber attackers are increasingly using Microsoft Teams to impersonate IT helpdesk staff, employing social engineering tactics to gain remote access to enterprise systems. This method, known as 'cross-tenant helpdesk…
T1021.002 - SMB/Windows Admin Shares is a mitre_attack tracked by ThreatCluster, appearing in 11 threat clusters built from 12 intelligence report mentions.
The most recent intelligence report mentioning T1021.002 - SMB/Windows Admin Shares on ThreatCluster is dated July 23, 2026. Activity was first observed April 22, 2026, giving a tracked span from then to July 23, 2026.
Across ThreatCluster reporting, T1021.002 - SMB/Windows Admin Shares most frequently co-occurs with Apt32, Apt38, Apt44, Cavern Manticore, Equation Group, among 12 tracked related entities.
The most significant recent cluster is “MuddyWater Targets U.S. Entities Amid Geopolitical Tensions” (16 articles · Updated July 22, 2026). T1021.002 - SMB/Windows Admin Shares appears across 11 threat clusters in total, listed above with sources.
T1021.002 - SMB/Windows Admin Shares appears in 12 intelligence report mentions across 11 deduplicated threat clusters, aggregated from 17,000+ monitored sources.