Activity timeline
T1543.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 19 reports, and 78 of the 78 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1543.003 Windows Service is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1543 Create or Modify System Process. Threadlinqs maps 78 of 2623 tracked threats (3%) to it; by severity that is 19 critical, 54 high, 5 medium.
Threats that use T1543.003 most often also use T1071.001 Web Protocols (55 threats), T1685 Disable or Modify Tools (48 threats), T1027 Obfuscated Files or Information (46 threats), T1059.001 PowerShell (42 threats), T1082 System Information Discovery (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
43 tracked threat actors appear in the threats that use T1543.003; the most frequent are APT38 (4), GhostEmperor (4), Midnight Blizzard (4), UNC2452 (4), Andariel (3).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1543.003.
Data sources
Telemetry that can reveal T1543.003, per MITRE ATT&CK.
- Command — Command Execution
- Driver — Driver Load
- File — File Metadata
- Network Traffic — Network Traffic Flow
- Process — OS API Execution, Process Creation
- Service — Service Creation, Service Modification
- Windows Registry — Windows Registry Key Creation, Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 78 tracked threats that use T1543.003.
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…high
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…high
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…high
- BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loadinghigh
- Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Accesshigh
- Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)critical
- Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…high
- Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum…high
- MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abusehigh
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…critical
- Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistencemedium
- SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV…medium
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitationcritical
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…high
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…critical
- PhantomStealer Infostealer Distributed via Phishing Campaign with BYOVD Security Software Killerhigh
- HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)high
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…high
- Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAThigh
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoorscritical
- N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…high
Detection coverage
Threadlinqs maintains 223 detection rules mapped to T1543.003 (SPL 90, KQL 68, Sigma 65). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1543 Create or Modify System Process — 232 tracked threats at the technique level.