Activity timeline
T1203 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 135 reports, and 363 of the 363 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1203 Exploitation for Client Execution is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 363 of 2623 tracked threats (13.8%) to it; by severity that is 197 critical, 137 high, 22 medium.
Threats that use T1203 most often also use T1190 Exploit Public-Facing Application (234 threats), T1068 Exploitation for Privilege Escalation (228 threats), T1082 System Information Discovery (207 threats), T1005 Data from Local System (204 threats), T1059 Command and Scripting Interpreter (192 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
60 tracked threat actors appear in the threats that use T1203; the most frequent are APT28 (9), Forest Blizzard (8), BlueDelta (6), APT38 (4), Andariel (4).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1203.
Data sources
Telemetry that can reveal T1203, per MITRE ATT&CK.
- Application Log — Application Log Content
- File — File Modification
- Network Traffic — Network Traffic Flow
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 363 tracked threats that use T1203.
- Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369…high
- Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on…medium
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)critical
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)critical
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)critical
- Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses…high
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attackshigh
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…medium
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)high
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Installcritical
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Linkcritical
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…high
- Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and…critical
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…high
- Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write…critical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…critical
- OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and…critical
- Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusionhigh
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…high
- UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…critical
- Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)critical
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…critical
- Multiple Zscaler Client Connector Flaws Enable Remote Code Execution (CVE-2026-59568)critical
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…high
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…critical
Detection coverage
Threadlinqs maintains 530 detection rules mapped to T1203 (SPL 199, KQL 166, Sigma 165). Rule content is available to Blue tier accounts and above; this page shows counts only.