Activity timeline
T1543.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 7 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1543.004 Launch Daemon is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1543 Create or Modify System Process. Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 11 high, 1 medium.
Threats that use T1543.004 most often also use T1059.004 Unix Shell (12 threats), T1005 Data from Local System (11 threats), T1082 System Information Discovery (11 threats), T1027 Obfuscated Files or Information (10 threats), T1036.005 Match Legitimate Resource Name or Location (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
Mitigations
MITRE ATT&CK lists 2 mitigations for T1543.004.
Data sources
Telemetry that can reveal T1543.004, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Modification
- Process — Process Creation
- Service — Service Creation, Service Modification
Tracked threats
14 tracked threats use T1543.004.
- CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…high
- Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and…critical
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malwarehigh
- Post-DEF CON Phishing Campaign Abuses Google Apps Script Sidebar to Deliver AMOS Stealer and NetSupport RAThigh
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…high
- Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Commandmedium
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contracthigh
- macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain…high
- macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…high
- ClickFix macOS Trio: Loader/Script/Helper Campaigns Deliver SHub Stealer, AMOS, and Macsync Stealer with…high
Detection coverage
Threadlinqs maintains 35 detection rules mapped to T1543.004 (SPL 15, KQL 7, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1543 Create or Modify System Process — 232 tracked threats at the technique level.