Threadlinqs IntelligenceStart free

ATT&CK techniquePersistencePrivilege Escalation

T1037.004 RC Scripts

PersistencePrivilege EscalationEnterpriseSub-technique

As of 2026-10-05, T1037.004 (RC Scripts) appears in 18 tracked threats, first reported 2026-02-21 and most recently 2026-10-03, with linked actors including INC Ransomware, Qilin ransomware affiliate, UNC6201; it most often appears alongside T1059.004 (Unix Shell).

Tracked threats
1811 critical, 7 high
First seen
2026-02-21
Last seen
2026-10-03
Threat actors
4In the threats using it
Detection rules
37Blue tier and above

Data as of:

Activity timeline

T1037.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 18 of the 18 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1037.004 RC Scripts is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1037 Boot or Logon Initialization Scripts. Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 11 critical, 7 high.

Threats that use T1037.004 most often also use T1059.004 Unix Shell (16 threats), T1036.005 Match Legitimate Resource Name or Location (13 threats), T1190 Exploit Public-Facing Application (13 threats), T1572 Protocol Tunneling (13 threats), T1027 Obfuscated Files or Information (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1037.004; the most frequent are INC Ransomware (1), Qilin ransomware affiliate (1), UNC6201 (1), Velvet Ant (1).

Mitigations

MITRE ATT&CK lists 1 mitigation for T1037.004.

Data sources

Telemetry that can reveal T1037.004, per MITRE ATT&CK.

  • Command — Command Execution
  • File — File Creation, File Modification
  • Process — Process Creation

Threat actors using it

Tracked threats

18 tracked threats use T1037.004.

Detection coverage

Threadlinqs maintains 37 detection rules mapped to T1037.004 (SPL 14, KQL 11, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

37 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Parent technique

T1037 Boot or Logon Initialization Scripts — 29 tracked threats at the technique level.