# T1543.003 Windows Service

> As of 2026-10-05, T1543.003 (Windows Service) appears in 78 tracked threats, first reported 2026-02-04 and most recently 2026-10-01, with linked actors including APT38, GhostEmperor, Midnight Blizzard; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 78 (19 critical, 54 high, 5 medium)
- **First seen:** 2026-02-04
- **Last seen:** 2026-10-01
- **Threat actors:** 43
- **Detection rules:** 223 (counts only; Blue tier and above)

## Key facts

- **ID:** T1543.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1543
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1543/003/

## Activity timeline

T1543.003 first appeared in tracked threats on 2026-02-04 and was most recently reported on 2026-10-01. The busiest month was 2026-08 with 19 reports, and 78 of the 78 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1543.003 Windows Service is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1543 Create or Modify System Process](https://intel.threadlinqs.com/technique/T1543). Threadlinqs maps 78 of 2623 tracked threats (3%) to it; by severity that is 19 critical, 54 high, 5 medium.

Threats that use T1543.003 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (55 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (48 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (46 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (42 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

43 tracked threat actors appear in the threats that use T1543.003; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (4), [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) (4), [UNC2452](https://intel.threadlinqs.com/actor/UNC2452) (4), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (3).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1543.003.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1543.003, per MITRE ATT&CK.

- Command — Command Execution
- Driver — Driver Load
- File — File Metadata
- Network Traffic — Network Traffic Flow
- Process — OS API Execution, Process Creation
- Service — Service Creation, Service Modification
- Windows Registry — Windows Registry Key Creation, Windows Registry Key Modification

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 4
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 4
- [UNC2452](https://intel.threadlinqs.com/actor/UNC2452) — 4
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 3
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 3
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 3
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 3
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 2
- [Head Mare](https://intel.threadlinqs.com/actor/Head%20Mare) — 2
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 2

## Tracked threats

The 30 most recent of 78 tracked threats that use T1543.003.

- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…](https://intel.threadlinqs.com/threat/TL-2026-2685) — high — 2026-09-27
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…](https://intel.threadlinqs.com/threat/TL-2026-2645) — high — 2026-09-25
- [Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…](https://intel.threadlinqs.com/threat/TL-2026-2602) — high — 2026-09-21
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…](https://intel.threadlinqs.com/threat/TL-2026-2446) — high — 2026-09-11
- [BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2426) — high — 2026-09-10
- [Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Access](https://intel.threadlinqs.com/threat/TL-2026-2453) — high — 2026-09-09
- [Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2408) — critical — 2026-09-08
- [Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…](https://intel.threadlinqs.com/threat/TL-2026-2323) — high — 2026-09-03
- [Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum…](https://intel.threadlinqs.com/threat/TL-2026-2310) — high — 2026-09-03
- [MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abuse](https://intel.threadlinqs.com/threat/TL-2026-2288) — high — 2026-09-02
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-2162) — critical — 2026-08-27
- [Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistence](https://intel.threadlinqs.com/threat/TL-2026-2149) — medium — 2026-08-26
- [SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV…](https://intel.threadlinqs.com/threat/TL-2026-2136) — medium — 2026-08-24
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — critical — 2026-08-23
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…](https://intel.threadlinqs.com/threat/TL-2026-2091) — high — 2026-08-21
- [CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…](https://intel.threadlinqs.com/threat/TL-2026-2087) — critical — 2026-08-20
- [PhantomStealer Infostealer Distributed via Phishing Campaign with BYOVD Security Software Killer](https://intel.threadlinqs.com/threat/TL-2026-2055) — high — 2026-08-18
- [HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)](https://intel.threadlinqs.com/threat/TL-2026-2013) — high — 2026-08-14
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…](https://intel.threadlinqs.com/threat/TL-2026-2010) — high — 2026-08-13
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoors](https://intel.threadlinqs.com/threat/TL-2026-1982) — critical — 2026-08-11
- [N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…](https://intel.threadlinqs.com/threat/TL-2026-1941) — high — 2026-08-08

## Related CVEs

CVEs referenced by the tracked threats that use T1543.003, most frequent first.

- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-4345](https://intel.threadlinqs.com/cve/CVE-2024-4345)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-49704](https://intel.threadlinqs.com/cve/CVE-2025-49704)
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-68947](https://intel.threadlinqs.com/cve/CVE-2025-68947)
- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556)
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577)

## Detection coverage

Threadlinqs maintains 223 detection rules mapped to T1543.003 (SPL 90, KQL 68, Sigma 65). Rule content is available to Blue tier accounts and above; this page shows counts only.

223 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1543 Create or Modify System Process](https://intel.threadlinqs.com/technique/T1543) — 232 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1543.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
