# T1047 Windows Management Instrumentation

> As of 2026-10-05, T1047 (Windows Management Instrumentation) appears in 104 tracked threats, first reported 2026-01-19 and most recently 2026-10-03, with linked actors including MuddyWater, Chaos, ALPHV; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 104 (26 critical, 65 high, 12 medium)
- **First seen:** 2026-01-19
- **Last seen:** 2026-10-03
- **Threat actors:** 59
- **Detection rules:** 71 (counts only; Blue tier and above)

## Key facts

- **ID:** T1047
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1047/

## Activity timeline

T1047 first appeared in tracked threats on 2026-01-19 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 41 reports, and 104 of the 104 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1047 Windows Management Instrumentation is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 104 of 2623 tracked threats (4%) to it; by severity that is 26 critical, 65 high, 12 medium.

Threats that use T1047 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (65 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (62 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (60 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (60 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (53 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

59 tracked threat actors appear in the threats that use T1047; the most frequent are [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (6), [Chaos](https://intel.threadlinqs.com/actor/Chaos) (5), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (4), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) (3), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (3).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1047.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)

## Data sources

Telemetry that can reveal T1047, per MITRE ATT&CK.

- Command — Command Execution
- Network Traffic — Network Connection Creation
- Process — Process Creation
- WMI — WMI Creation

## Threat actors using it

- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 6
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 5
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 4
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 3
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 2
- [DeadLock](https://intel.threadlinqs.com/actor/DeadLock) — 2
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 2
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 2
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 2
- [Mustard Tempest](https://intel.threadlinqs.com/actor/Mustard%20Tempest) — 2

## Tracked threats

The 30 most recent of 104 tracked threats that use T1047.

- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions…](https://intel.threadlinqs.com/threat/TL-2026-2828) — medium — 2026-10-01
- [Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans](https://intel.threadlinqs.com/threat/TL-2026-2824) — high — 2026-10-01
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2554) — high — 2026-09-17
- [BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2](https://intel.threadlinqs.com/threat/TL-2026-2520) — high — 2026-09-15
- [Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass](https://intel.threadlinqs.com/threat/TL-2026-2481) — high — 2026-09-13
- [PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)](https://intel.threadlinqs.com/threat/TL-2026-2212) — high — 2026-08-29
- [Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused…](https://intel.threadlinqs.com/threat/TL-2026-2209) — high — 2026-08-28
- [TITAN Ransomware Claims AI Platform Analyzes 700GB of Stolen Data Per Hour](https://intel.threadlinqs.com/threat/TL-2026-2190) — high — 2026-08-28
- [SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2200) — high — 2026-08-19
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-2057) — high — 2026-08-18
- [Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)](https://intel.threadlinqs.com/threat/TL-2026-2045) — high — 2026-08-17
- [CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for…](https://intel.threadlinqs.com/threat/TL-2026-1932) — 2026-08-07
- [SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1880) — high — 2026-08-04
- [DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…](https://intel.threadlinqs.com/threat/TL-2026-1809) — high — 2026-08-01
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…](https://intel.threadlinqs.com/threat/TL-2026-1766) — critical — 2026-07-30
- [AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups](https://intel.threadlinqs.com/threat/TL-2026-1761) — medium — 2026-07-29
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…](https://intel.threadlinqs.com/threat/TL-2026-1734) — high — 2026-07-28
- [AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…](https://intel.threadlinqs.com/threat/TL-2026-1727) — high — 2026-07-27
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-1707) — high — 2026-07-26
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23
- [Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network Detection](https://intel.threadlinqs.com/threat/TL-2026-1661) — high — 2026-07-23

## Related CVEs

CVEs referenced by the tracked threats that use T1047, most frequent first.

- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2017-11882](https://intel.threadlinqs.com/cve/CVE-2017-11882)
- [CVE-2017-8570](https://intel.threadlinqs.com/cve/CVE-2017-8570)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-10189](https://intel.threadlinqs.com/cve/CVE-2020-10189)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)

## Detection coverage

Threadlinqs maintains 71 detection rules mapped to T1047 (SPL 25, KQL 29, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

71 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1047
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
