Activity timeline
T1098.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 5 reports, and 17 of the 17 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1098.004 SSH Authorized Keys is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1098 Account Manipulation. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 11 critical, 5 high, 1 medium.
Threats that use T1098.004 most often also use T1059.004 Unix Shell (13 threats), T1190 Exploit Public-Facing Application (13 threats), T1021.004 SSH (12 threats), T1005 Data from Local System (11 threats), T1552.001 Credentials In Files (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
3 tracked threat actors appear in the threats that use T1098.004; the most frequent are UAT-8616 (2), Velvet Ant (2), Salt Typhoon - G1045 (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1098.004.
Data sources
Telemetry that can reveal T1098.004, per MITRE ATT&CK.
- Command — Command Execution
- File — File Modification
- Process — Process Creation
Threat actors using it
Tracked threats
17 tracked threats use T1098.004.
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…high
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Executioncritical
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…medium
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…high
- Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage Persistencecritical
- CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710…critical
- LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…critical
- Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers…critical
- cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEVcritical
- CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitationcritical
- Malicious Go crypto Module — Rekoobe Linux Backdoor via golang.org/x/crypto Namespace Confusionhigh
- Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication…critical
Detection coverage
Threadlinqs maintains 51 detection rules mapped to T1098.004 (SPL 16, KQL 18, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1098 Account Manipulation — 288 tracked threats at the technique level.