Activity timeline
T1053.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 60 reports, and 216 of the 216 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1053.005 Scheduled Task is catalogued by MITRE ATT&CK under the Execution and Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1053 Scheduled Task/Job. Threadlinqs maps 216 of 2623 tracked threats (8.2%) to it; by severity that is 27 critical, 173 high, 16 medium.
Threats that use T1053.005 most often also use T1071.001 Web Protocols (157 threats), T1059.001 PowerShell (138 threats), T1082 System Information Discovery (128 threats), T1204.002 Malicious File (125 threats), T1027 Obfuscated Files or Information (123 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
70 tracked threat actors appear in the threats that use T1053.005; the most frequent are APT38 (5), Sapphire Sleet (5), Stardust Chollima (5), APT28 (4), APT36 (4).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1053.005.
Data sources
Telemetry that can reveal T1053.005, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Modification
- Network Traffic — Network Traffic Flow
- Process — Process Creation
- Scheduled Job — Scheduled Job Creation
- Windows Registry — Windows Registry Key Creation
Threat actors using it
Tracked threats
The 30 most recent of 216 tracked threats that use T1053.005.
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealerhigh
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…high
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panelmedium
- Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…medium
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…critical
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…high
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentialscritical
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…medium
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…critical
- SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…high
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…high
Detection coverage
Threadlinqs maintains 554 detection rules mapped to T1053.005 (SPL 227, KQL 182, Sigma 145). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1053 Scheduled Task/Job — 271 tracked threats at the technique level.