Activity timeline
T1543 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 65 reports, and 232 of the 232 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1543 Create or Modify System Process is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix. Threadlinqs maps 232 of 2623 tracked threats (8.8%) to it; by severity that is 97 critical, 121 high, 12 medium.
Threats that use T1543 most often also use T1059 Command and Scripting Interpreter (193 threats), T1071 Application Layer Protocol (165 threats), T1027 Obfuscated Files or Information (161 threats), T1082 System Information Discovery (155 threats), T1036 Masquerading (149 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
69 tracked threat actors appear in the threats that use T1543; the most frequent are TeamPCP (14), APT38 (7), Stardust Chollima (6), Andariel (5), Lazarus Group (5).
Mitigations
MITRE ATT&CK lists 9 mitigations for T1543.
Data sources
Telemetry that can reveal T1543, per MITRE ATT&CK.
- Command — Command Execution
- Container — Container Creation
- Driver — Driver Load
- File — File Creation, File Modification
- Process — OS API Execution, Process Creation
- Service — Service Creation, Service Modification
- Windows Registry — Windows Registry Key Creation, Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 232 tracked threats that use T1543.
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCEcritical
- CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…high
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- ClickFix Lures Deploy MacSync Stealer to Bypass macOS Securityhigh
- CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…critical
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…critical
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)critical
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)high
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)high
- SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governmentscritical
- Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…critical
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…critical
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- MacSync Stealer: Malvertising Campaign Impersonates Claude/Apple Support to Deploy macOS Infostealerhigh
- TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bankhigh
- CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Accesscritical
- Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…high
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…high
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code…critical
- CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted…high
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projectshigh
- AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scalemedium
- Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via…critical
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Servicehigh
- XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and…critical
- CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for…critical
Detection coverage
Threadlinqs maintains 68 detection rules mapped to T1543 (SPL 21, KQL 22, Sigma 25). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1543.001 Launch Agent — 57 tracked threats
- T1543.002 Systemd Service — 49 tracked threats
- T1543.003 Windows Service — 78 tracked threats
- T1543.004 Launch Daemon — 14 tracked threats
- T1543.005 Container Service — 1 tracked threat