# T1053 Scheduled Task/Job

> As of 2026-10-05, T1053 (Scheduled Task/Job) appears in 271 tracked threats, first reported 2021-11-25 and most recently 2026-09-27, with linked actors including APT28, Forest Blizzard, APT38; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 271 (94 critical, 162 high, 12 medium, 2 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-09-27
- **Threat actors:** 102
- **Detection rules:** 56 (counts only; Blue tier and above)

## Key facts

- **ID:** T1053
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution, Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1053/

## Activity timeline

T1053 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 77 reports, and 270 of the 271 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1053 Scheduled Task/Job is catalogued by MITRE ATT&CK under the Execution and Persistence and Privilege Escalation tactics in the Enterprise matrix. Threadlinqs maps 271 of 2623 tracked threats (10.3%) to it; by severity that is 94 critical, 162 high, 12 medium, 2 low.

Threats that use T1053 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (234 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (211 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (203 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (193 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (187 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

102 tracked threat actors appear in the threats that use T1053; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (8), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (7), [APT38](https://intel.threadlinqs.com/actor/APT38) (6), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (6), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (6).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1053.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1053, per MITRE ATT&CK.

- Command — Command Execution
- Container — Container Creation
- File — File Creation, File Modification
- Process — Process Creation
- Scheduled Job — Scheduled Job Creation

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 8
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 7
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 6
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 6
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 6
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 5
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 5
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 5
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 5
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 5
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 4

## Tracked threats

The 30 most recent of 271 tracked threats that use T1053.

- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2416) — high — 2026-09-09
- [QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-2397) — high — 2026-09-08
- [REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…](https://intel.threadlinqs.com/threat/TL-2026-2370) — high — 2026-09-07
- [Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2](https://intel.threadlinqs.com/threat/TL-2026-2368) — high — 2026-09-07
- [FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…](https://intel.threadlinqs.com/threat/TL-2026-2362) — high — 2026-09-06
- [StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2356) — critical — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…](https://intel.threadlinqs.com/threat/TL-2026-2304) — high — 2026-09-03
- [Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK](https://intel.threadlinqs.com/threat/TL-2026-2293) — high — 2026-09-02
- [Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion…](https://intel.threadlinqs.com/threat/TL-2026-2278) — high — 2026-09-01
- ["Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay](https://intel.threadlinqs.com/threat/TL-2026-2276) — high — 2026-09-01
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…](https://intel.threadlinqs.com/threat/TL-2026-2255) — medium — 2026-08-31
- [Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)](https://intel.threadlinqs.com/threat/TL-2026-2182) — high — 2026-08-28
- [SynkLoader: New Multi-Module Malware Family Distributed via Microsoft Teams Phishing Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2098) — high — 2026-08-21
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — high — 2026-08-21
- [SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2090) — critical — 2026-08-20
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [WordlistLoader Delivering Amatera (ACR Stealer) via ClearFake FakeCaptcha Campaigns](https://intel.threadlinqs.com/threat/TL-2026-2367) — high — 2026-08-18
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…](https://intel.threadlinqs.com/threat/TL-2026-2031) — high — 2026-08-16
- [Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2005) — high — 2026-08-13
- [TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bank](https://intel.threadlinqs.com/threat/TL-2026-1977) — high — 2026-08-10
- [Odysseus AI Workspace Remote Code Execution via Authorization Bypass — GHSA-xwhc-f36c-v5vm (CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-1921) — critical — 2026-08-06
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…](https://intel.threadlinqs.com/threat/TL-2026-1917) — high — 2026-08-06
- [CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code…](https://intel.threadlinqs.com/threat/TL-2026-1893) — critical — 2026-08-05

## Related CVEs

CVEs referenced by the tracked threats that use T1053, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-6895](https://intel.threadlinqs.com/cve/CVE-2023-6895)

## Detection coverage

Threadlinqs maintains 56 detection rules mapped to T1053 (SPL 20, KQL 18, Sigma 18). Rule content is available to Blue tier accounts and above; this page shows counts only.

56 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1053.001 At (Linux) — 0 tracked threats
- T1053.002 At — 1 tracked threat
- [T1053.003 Cron](https://intel.threadlinqs.com/technique/T1053.003) — 61 tracked threats
- T1053.004 Launchd — 1 tracked threat
- [T1053.005 Scheduled Task](https://intel.threadlinqs.com/technique/T1053.005) — 216 tracked threats
- T1053.006 Systemd Timers — 3 tracked threats
- T1053.007 Container Orchestration Job — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1053
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
