Activity timeline
T1543.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 11 reports, and 49 of the 49 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1543.002 Systemd Service is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1543 Create or Modify System Process. Threadlinqs maps 49 of 2623 tracked threats (1.9%) to it; by severity that is 27 critical, 19 high, 3 medium.
Threats that use T1543.002 most often also use T1071.001 Web Protocols (38 threats), T1059.004 Unix Shell (37 threats), T1036.005 Match Legitimate Resource Name or Location (34 threats), T1027 Obfuscated Files or Information (32 threats), T1005 Data from Local System (30 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
23 tracked threat actors appear in the threats that use T1543.002; the most frequent are TeamPCP (8), APT38 (5), Sapphire Sleet (5), Stardust Chollima (5), UNC1069 (4).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1543.002.
Data sources
Telemetry that can reveal T1543.002, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Modification
- Process — Process Creation
- Service — Service Creation, Service Modification
Threat actors using it
Tracked threats
The 30 most recent of 49 tracked threats that use T1543.002.
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)high
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…critical
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoringmedium
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoorcritical
- npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Wormcritical
- VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KBhigh
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2critical
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…critical
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…high
- Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoorcritical
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…critical
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attackcritical
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…critical
- 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)high
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…high
- SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machineshigh
- SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…high
- Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF Rootkithigh
- Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…high
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…critical
- AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Frameworkcritical
- EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver…high
- Sapphire Sleet (DPRK) 'easy-day-js' Supply-Chain Compromise of 140+ Mastra npm Packages via Hijacked…critical
- NCSC CEO Richard Horne: Hostile States Linked to Three-Quarters of Cyber Attacks on UK Critical National…medium
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…high
- Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage Persistencecritical
Detection coverage
Threadlinqs maintains 148 detection rules mapped to T1543.002 (SPL 50, KQL 43, Sigma 55). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1543 Create or Modify System Process — 232 tracked threats at the technique level.