# T1098.004 SSH Authorized Keys

> As of 2026-10-05, T1098.004 (SSH Authorized Keys) appears in 17 tracked threats, first reported 2026-02-26 and most recently 2026-09-30, with linked actors including UAT-8616, Velvet Ant, Salt Typhoon - G1045; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 17 (11 critical, 5 high, 1 medium)
- **First seen:** 2026-02-26
- **Last seen:** 2026-09-30
- **Threat actors:** 3
- **Detection rules:** 51 (counts only; Blue tier and above)

## Key facts

- **ID:** T1098.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1098
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1098/004/

## Activity timeline

T1098.004 first appeared in tracked threats on 2026-02-26 and was most recently reported on 2026-09-30. The busiest month was 2026-09 with 5 reports, and 17 of the 17 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1098.004 SSH Authorized Keys is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098). Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 11 critical, 5 high, 1 medium.

Threats that use T1098.004 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (13 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (13 threats), [T1021.004 SSH](https://intel.threadlinqs.com/technique/T1021.004) (12 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (11 threats), [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1098.004; the most frequent are [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) (2), [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) (2), [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1098.004.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1098.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Modification
- Process — Process Creation

## Threat actors using it

- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 2
- [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) — 2
- [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) — 1

## Tracked threats

17 tracked threats use T1098.004.

- [GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…](https://intel.threadlinqs.com/threat/TL-2026-2818) — critical — 2026-09-30
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2177) — critical — 2026-08-28
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…](https://intel.threadlinqs.com/threat/TL-2026-1156) — medium — 2026-07-03
- [Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…](https://intel.threadlinqs.com/threat/TL-2026-0809) — high — 2026-06-15
- [Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage Persistence](https://intel.threadlinqs.com/threat/TL-2026-0807) — critical — 2026-06-15
- [CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710…](https://intel.threadlinqs.com/threat/TL-2026-0738) — critical — 2026-06-09
- [LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…](https://intel.threadlinqs.com/threat/TL-2026-0565) — critical — 2026-05-22
- [Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers…](https://intel.threadlinqs.com/threat/TL-2026-0449) — critical — 2026-05-02
- [cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-0440) — critical — 2026-04-30
- [CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0166) — critical — 2026-03-02
- [Malicious Go crypto Module — Rekoobe Linux Backdoor via golang.org/x/crypto Namespace Confusion](https://intel.threadlinqs.com/threat/TL-2026-0164) — high — 2026-03-02
- [Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication…](https://intel.threadlinqs.com/threat/TL-2026-0145) — critical — 2026-02-26

## Related CVEs

CVEs referenced by the tracked threats that use T1098.004, most frequent first.

- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42271](https://intel.threadlinqs.com/cve/CVE-2026-42271)
- [CVE-2026-48710](https://intel.threadlinqs.com/cve/CVE-2026-48710)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-48172](https://intel.threadlinqs.com/cve/CVE-2026-48172)
- [CVE-2026-5027](https://intel.threadlinqs.com/cve/CVE-2026-5027)
- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2026-65660](https://intel.threadlinqs.com/cve/CVE-2026-65660)
- [CVE-2026-67276](https://intel.threadlinqs.com/cve/CVE-2026-67276)
- [CVE-2026-67277](https://intel.threadlinqs.com/cve/CVE-2026-67277)
- [CVE-2026-67278](https://intel.threadlinqs.com/cve/CVE-2026-67278)
- [CVE-2026-67279](https://intel.threadlinqs.com/cve/CVE-2026-67279)
- [CVE-2026-67281](https://intel.threadlinqs.com/cve/CVE-2026-67281)
- [CVE-2026-86060](https://intel.threadlinqs.com/cve/CVE-2026-86060)

## Detection coverage

Threadlinqs maintains 51 detection rules mapped to T1098.004 (SPL 16, KQL 18, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

51 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1098 Account Manipulation](https://intel.threadlinqs.com/technique/T1098) — 288 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1098.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
