# T1202 Indirect Command Execution

> As of 2026-10-05, T1202 (Indirect Command Execution) appears in 21 tracked threats, first reported 2026-01-01 and most recently 2026-10-02, with linked actors including APT38, UNC6692, APT-C-60; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 21 (7 critical, 13 high, 1 medium)
- **First seen:** 2026-01-01
- **Last seen:** 2026-10-02
- **Threat actors:** 15
- **Detection rules:** 17 (counts only; Blue tier and above)

## Key facts

- **ID:** T1202
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1202/

## Activity timeline

T1202 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 5 reports, and 21 of the 21 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1202 Indirect Command Execution is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 7 critical, 13 high, 1 medium.

Threats that use T1202 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (19 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (17 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (15 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (15 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

15 tracked threat actors appear in the threats that use T1202; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) (2), [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) (1), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (1), [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) (1).

## Data sources

Telemetry that can reveal T1202, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) — 2
- [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) — 1
- [DriveSurge](https://intel.threadlinqs.com/actor/DriveSurge) — 1
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Star Blizzard](https://intel.threadlinqs.com/actor/Star%20Blizzard) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [TraderTraitor](https://intel.threadlinqs.com/actor/TraderTraitor) — 1

## Tracked threats

21 tracked threats use T1202.

- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2090) — critical — 2026-08-20
- [Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1901) — critical — 2026-08-05
- [ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…](https://intel.threadlinqs.com/threat/TL-2026-1872) — critical — 2026-08-04
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…](https://intel.threadlinqs.com/threat/TL-2026-1379) — high — 2026-07-15
- [EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1191) — high — 2026-07-10
- [ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector…](https://intel.threadlinqs.com/threat/TL-2026-1127) — high — 2026-07-05
- [ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software…](https://intel.threadlinqs.com/threat/TL-2026-1040) — high — 2026-07-01
- [CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via…](https://intel.threadlinqs.com/threat/TL-2026-1000) — critical — 2026-06-30
- [APT-C-60 Spear-Phishing Campaign Deploying SpyGlace Spyware (v3.1.12-3.1.14) via VHDX/LNK and Git (gcmd.exe)…](https://intel.threadlinqs.com/threat/TL-2026-0777) — high — 2026-06-11
- [UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams Helpdesk Impersonation…](https://intel.threadlinqs.com/threat/TL-2026-0423) — high — 2026-04-25
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoning](https://intel.threadlinqs.com/threat/TL-2026-0332) — high — 2026-04-07
- [EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interview](https://intel.threadlinqs.com/threat/TL-2026-0293) — critical — 2026-03-27
- [Silver Fox APT Tax-Themed Phishing Campaigns Deploying ValleyRAT, BYOVD Driver Abuse, and Kernel Rootkits](https://intel.threadlinqs.com/threat/TL-2026-0276) — high — 2026-03-24
- [KongTuke ClickFix Campaign — ModeloRAT Deployment via Compromised WordPress Sites and CrashFix Browser…](https://intel.threadlinqs.com/threat/TL-2026-0208) — high — 2026-03-10
- [ChainedShark APT (Actor240820): State-Sponsored Espionage Targeting Chinese Research Institutions via…](https://intel.threadlinqs.com/threat/TL-2026-0082) — medium — 2026-02-13
- [DockerDash: Critical Ask Gordon AI Vulnerability - Code Execution via Image Metadata](https://intel.threadlinqs.com/threat/TL-2026-0059) — critical — 2026-02-03
- [UNC5142 EtherHiding: BNB Smart Chain-Based Malware Distribution via Compromised WordPress Sites](https://intel.threadlinqs.com/threat/TL-2026-1512) — high — 2026-01-01

## Related CVEs

CVEs referenced by the tracked threats that use T1202, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)

## Detection coverage

Threadlinqs maintains 17 detection rules mapped to T1202 (SPL 6, KQL 4, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

17 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1202
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
