# T1003.007 Proc Filesystem

> As of 2026-10-05, T1003.007 (Proc Filesystem) appears in 10 tracked threats, first reported 2026-03-24 and most recently 2026-09-30, with linked actors including TeamPCP, Shai-Hulud; it most often appears alongside T1059.007 (JavaScript).

- **Tracked threats:** 10 (8 critical, 2 high)
- **First seen:** 2026-03-24
- **Last seen:** 2026-09-30
- **Threat actors:** 2
- **Detection rules:** 23 (counts only; Blue tier and above)

## Key facts

- **ID:** T1003.007
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1003
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1003/007/

## Activity timeline

T1003.007 first appeared in tracked threats on 2026-03-24 and was most recently reported on 2026-09-30. The busiest month was 2026-08 with 4 reports, and 10 of the 10 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1003.007 Proc Filesystem is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003). Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 8 critical, 2 high.

Threats that use T1003.007 most often also use [T1059.007 JavaScript](https://intel.threadlinqs.com/technique/T1059.007) (9 threats), [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (9 threats), [T1567.001 Exfiltration to Code Repository](https://intel.threadlinqs.com/technique/T1567.001) (9 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (8 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1003.007; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (7), [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1003.007.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)

## Data sources

Telemetry that can reveal T1003.007, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 7
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 1

## Tracked threats

10 tracked threats use T1003.007.

- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — high — 2026-09-30
- [Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…](https://intel.threadlinqs.com/threat/TL-2026-2661) — high — 2026-09-26
- [npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm](https://intel.threadlinqs.com/threat/TL-2026-2193) — critical — 2026-08-28
- [GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)](https://intel.threadlinqs.com/threat/TL-2026-2130) — critical — 2026-08-24
- ['ChainDrop' self-propagating worm compromises hundreds of popular npm packages (keyv, cacheable ecosystem)…](https://intel.threadlinqs.com/threat/TL-2026-2822) — critical — 2026-08-04
- [Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)](https://intel.threadlinqs.com/threat/TL-2026-1861) — critical — 2026-08-04
- [Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…](https://intel.threadlinqs.com/threat/TL-2026-0547) — critical — 2026-05-21
- [Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCP](https://intel.threadlinqs.com/threat/TL-2026-0429) — critical — 2026-04-27
- [Bitwarden CLI 2026.4.0 (@bitwarden/cli) Compromised via Abused GitHub Action in Ongoing Checkmarx Supply…](https://intel.threadlinqs.com/threat/TL-2026-0417) — critical — 2026-04-23
- [TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem…](https://intel.threadlinqs.com/threat/TL-2026-0279) — critical — 2026-03-24

## Related CVEs

CVEs referenced by the tracked threats that use T1003.007, most frequent first.

- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-30154](https://intel.threadlinqs.com/cve/CVE-2025-30154)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)

## Detection coverage

Threadlinqs maintains 23 detection rules mapped to T1003.007 (SPL 10, KQL 9, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

23 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1003 OS Credential Dumping](https://intel.threadlinqs.com/technique/T1003) — 291 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1003.007
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
