# T1204 User Execution

> As of 2026-10-05, T1204 (User Execution) appears in 571 tracked threats, first reported 2022-04-07 and most recently 2026-09-29, with linked actors including APT38, Lazarus Group, Contagious Interview; it most often appears alongside T1071 (Application Layer Protocol).

- **Tracked threats:** 571 (123 critical, 384 high, 60 medium, 2 low)
- **First seen:** 2022-04-07
- **Last seen:** 2026-09-29
- **Threat actors:** 132
- **Detection rules:** 249 (counts only; Blue tier and above)

## Key facts

- **ID:** T1204
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1204/

## Activity timeline

T1204 first appeared in tracked threats on 2022-04-07 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 167 reports, and 570 of the 571 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1204 User Execution is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 571 of 2623 tracked threats (21.8%) to it; by severity that is 123 critical, 384 high, 60 medium, 2 low.

Threats that use T1204 most often also use [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (420 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (416 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (393 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (392 threats), [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (362 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

132 tracked threat actors appear in the threats that use T1204; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (17), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (14), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (13), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (13), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (13).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1204.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)

## Data sources

Telemetry that can reveal T1204, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- Container — Container Creation, Container Start
- File — File Creation
- Image — Image Creation
- Instance — Instance Creation, Instance Start
- Network Traffic — Network Connection Creation, Network Traffic Content
- Process — Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 17
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 14
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 13
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 13
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 13
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 13
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 12
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 11
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 10
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 9
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 9
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 8

## Tracked threats

The 30 most recent of 571 tracked threats that use T1204.

- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2707) — medium — 2026-09-27
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…](https://intel.threadlinqs.com/threat/TL-2026-2642) — high — 2026-09-24
- [North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…](https://intel.threadlinqs.com/threat/TL-2026-2577) — high — 2026-09-19
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…](https://intel.threadlinqs.com/threat/TL-2026-2573) — critical — 2026-09-18
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…](https://intel.threadlinqs.com/threat/TL-2026-2466) — critical — 2026-09-12
- [Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2456) — high — 2026-09-12
- [Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2452) — high — 2026-09-11
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security](https://intel.threadlinqs.com/threat/TL-2026-2434) — high — 2026-09-10
- [Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teams](https://intel.threadlinqs.com/threat/TL-2026-2430) — medium — 2026-09-10
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-2397) — high — 2026-09-08
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…](https://intel.threadlinqs.com/threat/TL-2026-2362) — high — 2026-09-06
- [ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2338) — high — 2026-09-05
- [BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…](https://intel.threadlinqs.com/threat/TL-2026-2315) — high — 2026-09-03
- [Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…](https://intel.threadlinqs.com/threat/TL-2026-2304) — high — 2026-09-03
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer/AMOS) Hijacking Claude AI…](https://intel.threadlinqs.com/threat/TL-2026-2262) — high — 2026-08-31
- [ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2256) — high — 2026-08-31
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…](https://intel.threadlinqs.com/threat/TL-2026-2255) — medium — 2026-08-31
- [Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync…](https://intel.threadlinqs.com/threat/TL-2026-2241) — high — 2026-08-30
- [Cybercriminals Build Fake School Websites and Phishing Domains as Education-Sector Attacks Hit Record High](https://intel.threadlinqs.com/threat/TL-2026-2236) — medium — 2026-08-30
- [TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India](https://intel.threadlinqs.com/threat/TL-2026-2202) — high — 2026-08-29
- [TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industry](https://intel.threadlinqs.com/threat/TL-2026-2175) — high — 2026-08-28

## Related CVEs

CVEs referenced by the tracked threats that use T1204, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-6895](https://intel.threadlinqs.com/cve/CVE-2023-6895)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-21893](https://intel.threadlinqs.com/cve/CVE-2024-21893)
- [CVE-2025-14174](https://intel.threadlinqs.com/cve/CVE-2025-14174)
- [CVE-2025-32711](https://intel.threadlinqs.com/cve/CVE-2025-32711)
- [CVE-2025-43529](https://intel.threadlinqs.com/cve/CVE-2025-43529)
- [CVE-2026-20700](https://intel.threadlinqs.com/cve/CVE-2026-20700)
- [CVE-2026-21514](https://intel.threadlinqs.com/cve/CVE-2026-21514)
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519)
- [CVE-2026-21522](https://intel.threadlinqs.com/cve/CVE-2026-21522)
- [CVE-2026-21525](https://intel.threadlinqs.com/cve/CVE-2026-21525)
- [CVE-2026-21532](https://intel.threadlinqs.com/cve/CVE-2026-21532)

## Detection coverage

Threadlinqs maintains 249 detection rules mapped to T1204 (SPL 89, KQL 81, Sigma 78, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

249 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) — 218 tracked threats
- [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) — 445 tracked threats
- [T1204.003 Malicious Image](https://intel.threadlinqs.com/technique/T1204.003) — 11 tracked threats
- [T1204.004 Malicious Copy and Paste](https://intel.threadlinqs.com/technique/T1204.004) — 59 tracked threats
- T1204.005 Malicious Library — 2 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1204
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
