Activity timeline
T1059.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 38 reports, and 150 of the 150 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1059.006 Python is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1059 Command and Scripting Interpreter. Threadlinqs maps 150 of 2623 tracked threats (5.7%) to it; by severity that is 61 critical, 82 high, 5 medium.
Threats that use T1059.006 most often also use T1071.001 Web Protocols (103 threats), T1005 Data from Local System (97 threats), T1027 Obfuscated Files or Information (94 threats), T1082 System Information Discovery (78 threats), T1041 Exfiltration Over C2 Channel (75 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
47 tracked threat actors appear in the threats that use T1059.006; the most frequent are TeamPCP (15), WageMole (5), APT38 (4), Contagious Interview (4), The Gentlemen (4).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1059.006.
Data sources
Telemetry that can reveal T1059.006, per MITRE ATT&CK.
- Command — Command Execution
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 150 tracked threats that use T1059.006.
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…high
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…high
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials…critical
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Cloudflare Containers cross-tenant residual disk data exposure via device-mapper thin-provisioning…high
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
- Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chainhigh
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…medium
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…high
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wildcritical
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow…high
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…medium
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2high
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalogcritical
- Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding…high
- Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase…critical
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…high
- Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacksmedium
- Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accountshigh
- Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interceptionhigh
Detection coverage
Threadlinqs maintains 441 detection rules mapped to T1059.006 (SPL 135, KQL 149, Sigma 149, other 8). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1059 Command and Scripting Interpreter — 1050 tracked threats at the technique level.