Activity timeline
T1059.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 95 reports, and 342 of the 342 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1059.001 PowerShell is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1059 Command and Scripting Interpreter. Threadlinqs maps 342 of 2623 tracked threats (13%) to it; by severity that is 71 critical, 240 high, 30 medium, 1 low.
Threats that use T1059.001 most often also use T1071.001 Web Protocols (230 threats), T1082 System Information Discovery (200 threats), T1027 Obfuscated Files or Information (198 threats), T1204.002 Malicious File (174 threats), T1036.005 Match Legitimate Resource Name or Location (173 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
116 tracked threat actors appear in the threats that use T1059.001; the most frequent are APT38 (17), Sapphire Sleet (14), Stardust Chollima (14), MuddyWater (7), UNC1069 (7).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1059.001.
Data sources
Telemetry that can reveal T1059.001, per MITRE ATT&CK.
- Command — Command Execution
- Module — Module Load
- Process — Process Creation, Process Metadata
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 342 tracked threats that use T1059.001.
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…high
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions…medium
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scanshigh
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threatcritical
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…medium
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…critical
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
Detection coverage
Threadlinqs maintains 1054 detection rules mapped to T1059.001 (SPL 416, KQL 327, Sigma 311). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1059 Command and Scripting Interpreter — 1050 tracked threats at the technique level.