Activity timeline
T1204 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 167 reports, and 570 of the 571 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1204 User Execution is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 571 of 2623 tracked threats (21.8%) to it; by severity that is 123 critical, 384 high, 60 medium, 2 low.
Threats that use T1204 most often also use T1071 Application Layer Protocol (420 threats), T1027 Obfuscated Files or Information (416 threats), T1059 Command and Scripting Interpreter (393 threats), T1036 Masquerading (392 threats), T1566 Phishing (362 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
132 tracked threat actors appear in the threats that use T1204; the most frequent are APT38 (17), Lazarus Group (14), Contagious Interview (13), Sapphire Sleet (13), Stardust Chollima (13).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1204.
Data sources
Telemetry that can reveal T1204, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- Container — Container Creation, Container Start
- File — File Creation
- Image — Image Creation
- Instance — Instance Creation, Instance Start
- Network Traffic — Network Connection Creation, Network Traffic Content
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 571 tracked threats that use T1204.
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…medium
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…high
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…high
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…critical
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonationhigh
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvestershigh
- SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attackshigh
- ClickFix Lures Deploy MacSync Stealer to Bypass macOS Securityhigh
- Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teamsmedium
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Servicehigh
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…high
- BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…high
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…high
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer/AMOS) Hijacking Claude AI…high
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…medium
- Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync…high
- Cybercriminals Build Fake School Websites and Phishing Domains as Education-Sector Attacks Hit Record Highmedium
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industryhigh
Detection coverage
Threadlinqs maintains 249 detection rules mapped to T1204 (SPL 89, KQL 81, Sigma 78, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1204.001 Malicious Link — 218 tracked threats
- T1204.002 Malicious File — 445 tracked threats
- T1204.003 Malicious Image — 11 tracked threats
- T1204.004 Malicious Copy and Paste — 59 tracked threats
- T1204.005 Malicious Library — 2 tracked threats