Activity timeline
T1059.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 79 reports, and 275 of the 276 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1059.004 Unix Shell is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1059 Command and Scripting Interpreter. Threadlinqs maps 276 of 2623 tracked threats (10.5%) to it; by severity that is 131 critical, 136 high, 9 medium.
Threats that use T1059.004 most often also use T1005 Data from Local System (165 threats), T1082 System Information Discovery (159 threats), T1071.001 Web Protocols (158 threats), T1190 Exploit Public-Facing Application (150 threats), T1552.001 Credentials In Files (122 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
55 tracked threat actors appear in the threats that use T1059.004; the most frequent are TeamPCP (9), APT38 (8), Sapphire Sleet (5), Stardust Chollima (5), UNC1069 (5).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1059.004.
Data sources
Telemetry that can reveal T1059.004, per MITRE ATT&CK.
- Command — Command Execution
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 276 tracked threats that use T1059.004.
- Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code…critical
- CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Cataloghigh
- BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…high
- Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft…critical
- AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…critical
- Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394high
- Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898…critical
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- CloudSyncD macOS Backdoor Delivered via Fake Zoom Installerhigh
- Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attackscritical
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)critical
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host fileshigh
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)high
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…high
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible…critical
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)high
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…critical
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…high
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…critical
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoringmedium
- CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)critical
Detection coverage
Threadlinqs maintains 898 detection rules mapped to T1059.004 (SPL 324, KQL 260, Sigma 314). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1059 Command and Scripting Interpreter — 1050 tracked threats at the technique level.