# T1053.003 Cron

> As of 2026-10-05, T1053.003 (Cron) appears in 61 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including JADEPUFFER, TeamPCP, WageMole; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 61 (36 critical, 23 high, 2 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-03
- **Threat actors:** 23
- **Detection rules:** 175 (counts only; Blue tier and above)

## Key facts

- **ID:** T1053.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution, Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1053
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1053/003/

## Activity timeline

T1053.003 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 20 reports, and 60 of the 61 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1053.003 Cron is catalogued by MITRE ATT&CK under the Execution and Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1053 Scheduled Task/Job](https://intel.threadlinqs.com/technique/T1053). Threadlinqs maps 61 of 2623 tracked threats (2.3%) to it; by severity that is 36 critical, 23 high, 2 medium.

Threats that use T1053.003 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (47 threats), [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (46 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (38 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (38 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (36 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

23 tracked threat actors appear in the threats that use T1053.003; the most frequent are [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) (2), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (2), [WageMole](https://intel.threadlinqs.com/actor/WageMole) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [APT32](https://intel.threadlinqs.com/actor/APT32) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1053.003.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1053.003, per MITRE ATT&CK.

- Command — Command Execution
- File — File Modification
- Process — Process Creation
- Scheduled Job — Scheduled Job Creation

## Threat actors using it

- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 2
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 2
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 1
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) — 1
- [Earth Lamia](https://intel.threadlinqs.com/actor/Earth%20Lamia) — 1
- [Magecart](https://intel.threadlinqs.com/actor/Magecart) — 1

## Tracked threats

The 30 most recent of 61 tracked threats that use T1053.003.

- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks](https://intel.threadlinqs.com/threat/TL-2026-2830) — critical — 2026-10-01
- [GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…](https://intel.threadlinqs.com/threat/TL-2026-2818) — critical — 2026-09-30
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…](https://intel.threadlinqs.com/threat/TL-2026-2639) — high — 2026-09-24
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2497) — critical — 2026-09-14
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2177) — critical — 2026-08-28
- [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://intel.threadlinqs.com/threat/TL-2026-2099) — critical — 2026-08-21
- [CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…](https://intel.threadlinqs.com/threat/TL-2026-2097) — critical — 2026-08-21
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2037) — critical — 2026-08-13
- [CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access](https://intel.threadlinqs.com/threat/TL-2026-1925) — critical — 2026-08-07
- [Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…](https://intel.threadlinqs.com/threat/TL-2026-1764) — critical — 2026-07-29
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…](https://intel.threadlinqs.com/threat/TL-2026-1703) — high — 2026-07-26
- [SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machines](https://intel.threadlinqs.com/threat/TL-2026-1575) — high — 2026-07-20
- [ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering…](https://intel.threadlinqs.com/threat/TL-2026-1551) — high — 2026-07-19
- [SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…](https://intel.threadlinqs.com/threat/TL-2026-1532) — high — 2026-07-19
- [Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…](https://intel.threadlinqs.com/threat/TL-2026-1496) — high — 2026-07-18
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…](https://intel.threadlinqs.com/threat/TL-2026-1440) — high — 2026-07-17
- [AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loader](https://intel.threadlinqs.com/threat/TL-2026-1387) — critical — 2026-07-15
- [AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Framework](https://intel.threadlinqs.com/threat/TL-2026-1360) — critical — 2026-07-15
- [Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink…](https://intel.threadlinqs.com/threat/TL-2026-1286) — high — 2026-07-13

## Related CVEs

CVEs referenced by the tracked threats that use T1053.003, most frequent first.

- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42271](https://intel.threadlinqs.com/cve/CVE-2026-42271)
- [CVE-2026-48710](https://intel.threadlinqs.com/cve/CVE-2026-48710)
- [CVE-2026-5027](https://intel.threadlinqs.com/cve/CVE-2026-5027)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2025-62593](https://intel.threadlinqs.com/cve/CVE-2025-62593)
- [CVE-2025-68613](https://intel.threadlinqs.com/cve/CVE-2025-68613)
- [CVE-2025-68668](https://intel.threadlinqs.com/cve/CVE-2025-68668)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-104286](https://intel.threadlinqs.com/cve/CVE-2026-104286)
- [CVE-2026-1357](https://intel.threadlinqs.com/cve/CVE-2026-1357)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-19489](https://intel.threadlinqs.com/cve/CVE-2026-19489)
- [CVE-2026-19490](https://intel.threadlinqs.com/cve/CVE-2026-19490)
- [CVE-2026-21858](https://intel.threadlinqs.com/cve/CVE-2026-21858)
- [CVE-2026-21877](https://intel.threadlinqs.com/cve/CVE-2026-21877)
- [CVE-2026-25049](https://intel.threadlinqs.com/cve/CVE-2026-25049)
- [CVE-2026-25052](https://intel.threadlinqs.com/cve/CVE-2026-25052)
- [CVE-2026-25053](https://intel.threadlinqs.com/cve/CVE-2026-25053)
- [CVE-2026-25056](https://intel.threadlinqs.com/cve/CVE-2026-25056)
- [CVE-2026-25115](https://intel.threadlinqs.com/cve/CVE-2026-25115)

## Detection coverage

Threadlinqs maintains 175 detection rules mapped to T1053.003 (SPL 56, KQL 52, Sigma 67). Rule content is available to Blue tier accounts and above; this page shows counts only.

175 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1053 Scheduled Task/Job](https://intel.threadlinqs.com/technique/T1053) — 271 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1053.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
