Activity timeline
T1202 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 21 of the 21 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1202 Indirect Command Execution is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 7 critical, 13 high, 1 medium.
Threats that use T1202 most often also use T1027 Obfuscated Files or Information (19 threats), T1082 System Information Discovery (17 threats), T1005 Data from Local System (15 threats), T1140 Deobfuscate/Decode Files or Information (15 threats), T1041 Exfiltration Over C2 Channel (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
15 tracked threat actors appear in the threats that use T1202; the most frequent are APT38 (2), UNC6692 (2), APT-C-60 (1), Andariel (1), Contagious Interview cluster (1).
Data sources
Telemetry that can reveal T1202, per MITRE ATT&CK.
- Command — Command Execution
- Process — Process Creation
Threat actors using it
Tracked threats
21 tracked threats use T1202.
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governmentscritical
- Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…critical
- ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…critical
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…high
- EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver…high
- ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector…high
- ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software…high
- CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via…critical
- APT-C-60 Spear-Phishing Campaign Deploying SpyGlace Spyware (v3.1.12-3.1.14) via VHDX/LNK and Git (gcmd.exe)…high
- UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams Helpdesk Impersonation…high
- UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…high
- DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoninghigh
- EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interviewcritical
- Silver Fox APT Tax-Themed Phishing Campaigns Deploying ValleyRAT, BYOVD Driver Abuse, and Kernel Rootkitshigh
- KongTuke ClickFix Campaign — ModeloRAT Deployment via Compromised WordPress Sites and CrashFix Browser…high
- ChainedShark APT (Actor240820): State-Sponsored Espionage Targeting Chinese Research Institutions via…medium
- DockerDash: Critical Ask Gordon AI Vulnerability - Code Execution via Image Metadatacritical
- UNC5142 EtherHiding: BNB Smart Chain-Based Malware Distribution via Compromised WordPress Siteshigh
Detection coverage
Threadlinqs maintains 17 detection rules mapped to T1202 (SPL 6, KQL 4, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.