Activity timeline
T1059.007 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 58 reports, and 240 of the 241 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1059.007 JavaScript is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1059 Command and Scripting Interpreter. Threadlinqs maps 241 of 2623 tracked threats (9.2%) to it; by severity that is 73 critical, 148 high, 17 medium, 2 low.
Threats that use T1059.007 most often also use T1071.001 Web Protocols (165 threats), T1027 Obfuscated Files or Information (151 threats), T1082 System Information Discovery (123 threats), T1005 Data from Local System (120 threats), T1204.002 Malicious File (109 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
65 tracked threat actors appear in the threats that use T1059.007; the most frequent are TeamPCP (19), Contagious Interview (9), APT38 (7), WageMole (7), Sapphire Sleet (6).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1059.007.
Data sources
Telemetry that can reveal T1059.007, per MITRE ATT&CK.
- Command — Command Execution
- Module — Module Load
- Process — Process Creation
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 241 tracked threats that use T1059.007.
- Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code…critical
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…critical
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…high
- Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to…critical
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on…medium
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)high
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)critical
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…medium
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)high
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…high
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)high
- Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via…high
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…high
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac usershigh
- Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin…high
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…high
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injectionmedium
- GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcphigh
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Installcritical
Detection coverage
Threadlinqs maintains 773 detection rules mapped to T1059.007 (SPL 283, KQL 239, Sigma 249, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1059 Command and Scripting Interpreter — 1050 tracked threats at the technique level.