Activity timeline
T1037.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 18 of the 18 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1037.004 RC Scripts is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1037 Boot or Logon Initialization Scripts. Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 11 critical, 7 high.
Threats that use T1037.004 most often also use T1059.004 Unix Shell (16 threats), T1036.005 Match Legitimate Resource Name or Location (13 threats), T1190 Exploit Public-Facing Application (13 threats), T1572 Protocol Tunneling (13 threats), T1027 Obfuscated Files or Information (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use T1037.004; the most frequent are INC Ransomware (1), Qilin ransomware affiliate (1), UNC6201 (1), Velvet Ant (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1037.004.
Data sources
Telemetry that can reveal T1037.004, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Modification
- Process — Process Creation
Threat actors using it
Tracked threats
18 tracked threats use T1037.004.
- Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394high
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…high
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…critical
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…critical
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…critical
- JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…high
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…high
- Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packagescritical
- Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…high
- UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware…critical
- Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…critical
Detection coverage
Threadlinqs maintains 37 detection rules mapped to T1037.004 (SPL 14, KQL 11, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1037 Boot or Logon Initialization Scripts — 29 tracked threats at the technique level.