# T1204.003 Malicious Image

> As of 2026-10-05, T1204.003 (Malicious Image) appears in 11 tracked threats, first reported 2026-04-25 and most recently 2026-09-30, with linked actors including TeamPCP, Shai-Hulud, UNC6780; it most often appears alongside T1552.001 (Credentials In Files).

- **Tracked threats:** 11 (2 critical, 9 high)
- **First seen:** 2026-04-25
- **Last seen:** 2026-09-30
- **Threat actors:** 3
- **Detection rules:** 33 (counts only; Blue tier and above)

## Key facts

- **ID:** T1204.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Parent:** T1204
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1204/003/

## Activity timeline

T1204.003 first appeared in tracked threats on 2026-04-25 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 5 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1204.003 Malicious Image is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of [T1204 User Execution](https://intel.threadlinqs.com/technique/T1204). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 2 critical, 9 high.

Threats that use T1204.003 most often also use [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (8 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (7 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (7 threats), [T1195.002 Compromise Software Supply Chain](https://intel.threadlinqs.com/technique/T1195.002) (7 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1204.003; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (4), [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) (2), [UNC6780](https://intel.threadlinqs.com/actor/UNC6780) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1204.003.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1204.003, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- Container — Container Creation, Container Start
- Image — Image Creation
- Instance — Instance Creation, Instance Start

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 4
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 2
- [UNC6780](https://intel.threadlinqs.com/actor/UNC6780) — 1

## Tracked threats

11 tracked threats use T1204.003.

- [Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files](https://intel.threadlinqs.com/threat/TL-2026-2812) — high — 2026-09-30
- [SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machines](https://intel.threadlinqs.com/threat/TL-2026-1575) — high — 2026-07-20
- [Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force…](https://intel.threadlinqs.com/threat/TL-2026-1240) — high — 2026-07-11
- [jscrambler npm Package Supply Chain Compromise (v8.14.0 Malicious Release)](https://intel.threadlinqs.com/threat/TL-2026-1233) — high — 2026-07-11
- [Braintree.Net NuGet Typosquat Uses XOR-Obfuscated WebSocket/HTTPS C2 to Exfiltrate Live Payment Card Data…](https://intel.threadlinqs.com/threat/TL-2026-1165) — high — 2026-07-10
- [npm Supply Chain Attack: @injectivelabs/sdk-ts v1.20.21 and 17 Sibling Packages Infected with Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1153) — high — 2026-07-09
- [Claude Code MCP Traffic Hijack via Malicious npm postinstall — ~/.claude.json Tampering Proxies MCP…](https://intel.threadlinqs.com/threat/TL-2026-0712) — high — 2026-06-08
- [Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm…](https://intel.threadlinqs.com/threat/TL-2026-1234) — high — 2026-06-04
- [lightning PyPI Package Compromise — Versions 2.6.2 & 2.6.3 Execute Bun-Based JavaScript Credential Stealer…](https://intel.threadlinqs.com/threat/TL-2026-0444) — critical — 2026-04-30
- [Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCP](https://intel.threadlinqs.com/threat/TL-2026-0429) — critical — 2026-04-27
- [Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2…](https://intel.threadlinqs.com/threat/TL-2026-0424) — high — 2026-04-25

## Related CVEs

CVEs referenced by the tracked threats that use T1204.003, most frequent first.

- [CVE-2026-17106](https://intel.threadlinqs.com/cve/CVE-2026-17106)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)

## Detection coverage

Threadlinqs maintains 33 detection rules mapped to T1204.003 (SPL 13, KQL 12, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

33 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1204 User Execution](https://intel.threadlinqs.com/technique/T1204) — 571 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1204.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
