Activity timeline
T1059.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 54 reports, and 205 of the 205 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1059.003 Windows Command Shell is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1059 Command and Scripting Interpreter. Threadlinqs maps 205 of 2623 tracked threats (7.8%) to it; by severity that is 39 critical, 153 high, 13 medium.
Threats that use T1059.003 most often also use T1071.001 Web Protocols (143 threats), T1082 System Information Discovery (137 threats), T1059.001 PowerShell (131 threats), T1027 Obfuscated Files or Information (120 threats), T1140 Deobfuscate/Decode Files or Information (112 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
100 tracked threat actors appear in the threats that use T1059.003; the most frequent are APT38 (9), Lazarus Group (8), Andariel (7), APT43 (5), Kimsuky (5).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1059.003.
Data sources
Telemetry that can reveal T1059.003, per MITRE ATT&CK.
- Command — Command Execution
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 205 tracked threats that use T1059.003.
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…high
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user…high
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…medium
- BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…high
- CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry…high
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chainhigh
- Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Accesshigh
- Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)critical
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoChigh
- FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…high
- Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…high
- Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum…high
- Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accountshigh
- Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…high
Detection coverage
Threadlinqs maintains 411 detection rules mapped to T1059.003 (SPL 172, KQL 111, Sigma 128). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1059 Command and Scripting Interpreter — 1050 tracked threats at the technique level.