# T1037.004 RC Scripts

> As of 2026-10-05, T1037.004 (RC Scripts) appears in 18 tracked threats, first reported 2026-02-21 and most recently 2026-10-03, with linked actors including INC Ransomware, Qilin ransomware affiliate, UNC6201; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 18 (11 critical, 7 high)
- **First seen:** 2026-02-21
- **Last seen:** 2026-10-03
- **Threat actors:** 4
- **Detection rules:** 37 (counts only; Blue tier and above)

## Key facts

- **ID:** T1037.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1037
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1037/004/

## Activity timeline

T1037.004 first appeared in tracked threats on 2026-02-21 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 5 reports, and 18 of the 18 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1037.004 RC Scripts is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1037 Boot or Logon Initialization Scripts](https://intel.threadlinqs.com/technique/T1037). Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 11 critical, 7 high.

Threats that use T1037.004 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (16 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (13 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (13 threats), [T1572 Protocol Tunneling](https://intel.threadlinqs.com/technique/T1572) (13 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1037.004; the most frequent are [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) (1), [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate) (1), [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) (1), [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1037.004.

- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)

## Data sources

Telemetry that can reveal T1037.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Process — Process Creation

## Threat actors using it

- [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) — 1
- [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate) — 1
- [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) — 1
- [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) — 1

## Tracked threats

18 tracked threats use T1037.004.

- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — high — 2026-10-03
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…](https://intel.threadlinqs.com/threat/TL-2026-2639) — high — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- [CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…](https://intel.threadlinqs.com/threat/TL-2026-2097) — critical — 2026-08-21
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1462) — critical — 2026-07-17
- [JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…](https://intel.threadlinqs.com/threat/TL-2026-1142) — high — 2026-07-06
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…](https://intel.threadlinqs.com/threat/TL-2026-0809) — high — 2026-06-15
- [Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-0979) — critical — 2026-06-12
- [Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…](https://intel.threadlinqs.com/threat/TL-2026-0456) — high — 2026-05-04
- [UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware…](https://intel.threadlinqs.com/threat/TL-2026-0221) — critical — 2026-03-13
- [Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…](https://intel.threadlinqs.com/threat/TL-2026-0123) — critical — 2026-02-21

## Related CVEs

CVEs referenced by the tracked threats that use T1037.004, most frequent first.

- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2021-35394](https://intel.threadlinqs.com/cve/CVE-2021-35394)
- [CVE-2022-22948](https://intel.threadlinqs.com/cve/CVE-2022-22948)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20867](https://intel.threadlinqs.com/cve/CVE-2023-20867)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-34048](https://intel.threadlinqs.com/cve/CVE-2023-34048)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-21590](https://intel.threadlinqs.com/cve/CVE-2025-21590)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-62593](https://intel.threadlinqs.com/cve/CVE-2025-62593)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-76460](https://intel.threadlinqs.com/cve/CVE-2026-76460)
- [CVE-2026-83548](https://intel.threadlinqs.com/cve/CVE-2026-83548)
- [CVE-2026-83549](https://intel.threadlinqs.com/cve/CVE-2026-83549)
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102)
- [CVE-2026-85103](https://intel.threadlinqs.com/cve/CVE-2026-85103)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)

## Detection coverage

Threadlinqs maintains 37 detection rules mapped to T1037.004 (SPL 14, KQL 11, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

37 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1037 Boot or Logon Initialization Scripts](https://intel.threadlinqs.com/technique/T1037) — 29 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1037.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
