Activity timeline
T1047 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 41 reports, and 104 of the 104 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1047 Windows Management Instrumentation is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 104 of 2623 tracked threats (4%) to it; by severity that is 26 critical, 65 high, 12 medium.
Threats that use T1047 most often also use T1082 System Information Discovery (65 threats), T1027 Obfuscated Files or Information (62 threats), T1105 Ingress Tool Transfer (60 threats), T1685 Disable or Modify Tools (60 threats), T1059 Command and Scripting Interpreter (53 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
59 tracked threat actors appear in the threats that use T1047; the most frequent are MuddyWater (6), Chaos (5), ALPHV (4), BlackCat (3), The Gentlemen (3).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1047.
Data sources
Telemetry that can reveal T1047, per MITRE ATT&CK.
- Command — Command Execution
- Network Traffic — Network Connection Creation
- Process — Process Creation
- WMI — WMI Creation
Threat actors using it
Tracked threats
The 30 most recent of 104 tracked threats that use T1047.
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions…medium
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scanshigh
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…high
- BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2high
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypasshigh
- PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)high
- Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused…high
- TITAN Ransomware Claims AI Platform Analyzes 700GB of Stolen Data Per Hourhigh
- SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governmentshigh
- SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asiahigh
- StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…high
- Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)high
- CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for…
- SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Accesshigh
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…high
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…critical
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groupsmedium
- Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resiliencehigh
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…high
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)high
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
- Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network Detectionhigh
Detection coverage
Threadlinqs maintains 71 detection rules mapped to T1047 (SPL 25, KQL 29, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.