T1069 - Permission Groups Discovery - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
April 17, 2026
Last Seen
July 8, 2026

T1069 - Permission Groups Discovery is a mitre_attack tracked across 6 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed April 17, 2026; most recent activity July 8, 2026.

Related Threat Clusters

  • Attackers Exploit WDigest Vulnerability to Harvest Plaintext Credentials

    A multi-stage cyber attack targeted IIS servers, beginning with enumeration commands and escalating to credential extraction using Mimikatz. The attackers uploaded a steganographic webshell and executed a…

    3 articles · Updated July 2, 2026
  • Storm-2949 Cyberattack Targets Microsoft 365 and Azure Data

    Microsoft has reported a significant cyberattack by the threat actor Storm-2949, which exploited Microsoft Entra ID accounts to conduct a large-scale data theft from Microsoft 365 and Azure environments. The attack…

    6 articles · Updated May 19, 2026
  • Akira Ransomware Attack Exploits Disabled VPN Account

    A recent Akira ransomware attack targeted a mid-sized organization by exploiting a disabled local SSL VPN account through brute-force methods. The attackers gained initial access, performed credential discovery, and…

    2 articles · Updated May 29, 2026
  • AI-Driven Malware Framework Automates EDR Evasion Tactics

    Sophos X-Ops analysts uncovered a threat actor utilizing AI technologies to develop a malware-testing framework aimed at evading endpoint detection and response (EDR) systems. The activity was detected on June 2, 2026,…

    16 articles · Updated June 2, 2026
  • Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware

    Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…

    8 articles · Updated April 17, 2026
  • AI-Generated Malware Exploits Active Directory via Vibe Coding

    A threat actor utilized AI-generated malware to infiltrate a network on June 3, 2026, employing a PowerShell script created through a method called vibe coding. This technique allows attackers to generate custom scripts…

    4 articles · Updated July 9, 2026

Recent Intelligence Reports

  • AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration — Huntress · July 8, 2026
  • Attackers Downgrade WDigest Protection to Dump Plaintext Credentials With Mimikatz — Gbhackers · July 2, 2026
  • AI-built ransomware toolkit automates EDR evasion, AD discovery — Bleepingcomputer · June 2, 2026
  • Akira Ransomware Kill Chain Reconstructed from Logs — Socprime · May 29, 2026
  • Microsoft Details Storm — Thecyberexpress · May 19, 2026
  • Hackers dodging security tools by dropping secret QEMU virtual machines inside Windows — Cybernews · April 17, 2026

CVSS v3.1 Breakdown