# T1053.005 Scheduled Task

> As of 2026-10-05, T1053.005 (Scheduled Task) appears in 216 tracked threats, first reported 2026-01-14 and most recently 2026-10-03, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 216 (27 critical, 173 high, 16 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-03
- **Threat actors:** 70
- **Detection rules:** 554 (counts only; Blue tier and above)

## Key facts

- **ID:** T1053.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution, Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1053
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1053/005/

## Activity timeline

T1053.005 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 60 reports, and 216 of the 216 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1053.005 Scheduled Task is catalogued by MITRE ATT&CK under the Execution and Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1053 Scheduled Task/Job](https://intel.threadlinqs.com/technique/T1053). Threadlinqs maps 216 of 2623 tracked threats (8.2%) to it; by severity that is 27 critical, 173 high, 16 medium.

Threats that use T1053.005 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (157 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (138 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (128 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (125 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (123 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

70 tracked threat actors appear in the threats that use T1053.005; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (5), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (5), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (5), [APT28](https://intel.threadlinqs.com/actor/APT28) (4), [APT36](https://intel.threadlinqs.com/actor/APT36) (4).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1053.005.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1053.005, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Network Traffic — Network Traffic Flow
- Process — Process Creation
- Scheduled Job — Scheduled Job Creation
- Windows Registry — Windows Registry Key Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 5
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 5
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 5
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 4
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 4
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 4
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 4
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 4
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 4
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 4
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 4
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 4

## Tracked threats

The 30 most recent of 216 tracked threats that use T1053.005.

- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — high — 2026-09-30
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2800) — high — 2026-09-30
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…](https://intel.threadlinqs.com/threat/TL-2026-2773) — high — 2026-09-29
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer](https://intel.threadlinqs.com/threat/TL-2026-2699) — high — 2026-09-27
- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…](https://intel.threadlinqs.com/threat/TL-2026-2685) — high — 2026-09-27
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2664) — high — 2026-09-26
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…](https://intel.threadlinqs.com/threat/TL-2026-2631) — high — 2026-09-23
- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panel](https://intel.threadlinqs.com/threat/TL-2026-2621) — medium — 2026-09-22
- [Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…](https://intel.threadlinqs.com/threat/TL-2026-2615) — medium — 2026-09-22
- [Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systems](https://intel.threadlinqs.com/threat/TL-2026-2612) — medium — 2026-09-22
- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…](https://intel.threadlinqs.com/threat/TL-2026-2606) — critical — 2026-09-21
- [Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…](https://intel.threadlinqs.com/threat/TL-2026-2604) — high — 2026-09-21
- [EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials](https://intel.threadlinqs.com/threat/TL-2026-2600) — critical — 2026-09-21
- [PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…](https://intel.threadlinqs.com/threat/TL-2026-2593) — medium — 2026-09-20
- [Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…](https://intel.threadlinqs.com/threat/TL-2026-2561) — critical — 2026-09-18
- [SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2554) — high — 2026-09-17
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…](https://intel.threadlinqs.com/threat/TL-2026-2544) — high — 2026-09-16

## Related CVEs

CVEs referenced by the tracked threats that use T1053.005, most frequent first.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-50656](https://intel.threadlinqs.com/cve/CVE-2026-50656)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-0708](https://intel.threadlinqs.com/cve/CVE-2019-0708)
- [CVE-2019-16098](https://intel.threadlinqs.com/cve/CVE-2019-16098)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2022-2586](https://intel.threadlinqs.com/cve/CVE-2022-2586)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-37042](https://intel.threadlinqs.com/cve/CVE-2022-37042)

## Detection coverage

Threadlinqs maintains 554 detection rules mapped to T1053.005 (SPL 227, KQL 182, Sigma 145). Rule content is available to Blue tier accounts and above; this page shows counts only.

554 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1053 Scheduled Task/Job](https://intel.threadlinqs.com/technique/T1053) — 271 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1053.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
