# T1059.006 Python

> As of 2026-10-05, T1059.006 (Python) appears in 150 tracked threats, first reported 2026-02-04 and most recently 2026-10-04, with linked actors including TeamPCP, WageMole, APT38; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 150 (61 critical, 82 high, 5 medium)
- **First seen:** 2026-02-04
- **Last seen:** 2026-10-04
- **Threat actors:** 47
- **Detection rules:** 441 (counts only; Blue tier and above)

## Key facts

- **ID:** T1059.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Parent:** T1059
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1059/006/

## Activity timeline

T1059.006 first appeared in tracked threats on 2026-02-04 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 38 reports, and 150 of the 150 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1059.006 Python is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059). Threadlinqs maps 150 of 2623 tracked threats (5.7%) to it; by severity that is 61 critical, 82 high, 5 medium.

Threats that use T1059.006 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (103 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (97 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (94 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (78 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (75 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

47 tracked threat actors appear in the threats that use T1059.006; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (15), [WageMole](https://intel.threadlinqs.com/actor/WageMole) (5), [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (4), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (4).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1059.006.

- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1059.006, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 15
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 5
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 4
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 4
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 3
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 3
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 3
- [UNC5342](https://intel.threadlinqs.com/actor/UNC5342) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 2

## Tracked threats

The 30 most recent of 150 tracked threats that use T1059.006.

- [TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…](https://intel.threadlinqs.com/threat/TL-2026-2889) — high — 2026-10-04
- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…](https://intel.threadlinqs.com/threat/TL-2026-2818) — critical — 2026-09-30
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2800) — high — 2026-09-30
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials…](https://intel.threadlinqs.com/threat/TL-2026-2772) — critical — 2026-09-29
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Cloudflare Containers cross-tenant residual disk data exposure via device-mapper thin-provisioning…](https://intel.threadlinqs.com/threat/TL-2026-2644) — high — 2026-09-24
- [Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systems](https://intel.threadlinqs.com/threat/TL-2026-2612) — medium — 2026-09-22
- [Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain](https://intel.threadlinqs.com/threat/TL-2026-2601) — high — 2026-09-21
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…](https://intel.threadlinqs.com/threat/TL-2026-2581) — high — 2026-09-19
- [Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-2574) — critical — 2026-09-19
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow…](https://intel.threadlinqs.com/threat/TL-2026-2572) — high — 2026-09-18
- [AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…](https://intel.threadlinqs.com/threat/TL-2026-2559) — medium — 2026-09-18
- [EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2](https://intel.threadlinqs.com/threat/TL-2026-2547) — high — 2026-09-17
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2508) — critical — 2026-09-14
- [Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding…](https://intel.threadlinqs.com/threat/TL-2026-2484) — high — 2026-09-13
- [Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase…](https://intel.threadlinqs.com/threat/TL-2026-2438) — critical — 2026-09-10
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…](https://intel.threadlinqs.com/threat/TL-2026-2390) — high — 2026-09-08
- [Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-2299) — medium — 2026-09-02
- [Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts](https://intel.threadlinqs.com/threat/TL-2026-2296) — high — 2026-09-02
- [Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception](https://intel.threadlinqs.com/threat/TL-2026-2294) — high — 2026-09-02

## Related CVEs

CVEs referenced by the tracked threats that use T1059.006, most frequent first.

- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-42271](https://intel.threadlinqs.com/cve/CVE-2026-42271)
- [CVE-2026-48710](https://intel.threadlinqs.com/cve/CVE-2026-48710)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-25592](https://intel.threadlinqs.com/cve/CVE-2026-25592)
- [CVE-2026-26030](https://intel.threadlinqs.com/cve/CVE-2026-26030)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2026-5027](https://intel.threadlinqs.com/cve/CVE-2026-5027)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)

## Detection coverage

Threadlinqs maintains 441 detection rules mapped to T1059.006 (SPL 135, KQL 149, Sigma 149, other 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

441 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) — 1050 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1059.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
