# T1543.004 Launch Daemon

> As of 2026-10-05, T1543.004 (Launch Daemon) appears in 14 tracked threats, first reported 2026-05-06 and most recently 2026-09-16; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 14 (2 critical, 11 high, 1 medium)
- **First seen:** 2026-05-06
- **Last seen:** 2026-09-16
- **Detection rules:** 35 (counts only; Blue tier and above)

## Key facts

- **ID:** T1543.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1543
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1543/004/

## Activity timeline

T1543.004 first appeared in tracked threats on 2026-05-06 and was most recently reported on 2026-09-16. The busiest month was 2026-08 with 7 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1543.004 Launch Daemon is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1543 Create or Modify System Process](https://intel.threadlinqs.com/technique/T1543). Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 11 high, 1 medium.

Threats that use T1543.004 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (12 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (11 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (11 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1543.004.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1543.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Process — Process Creation
- Service — Service Creation, Service Modification

## Tracked threats

14 tracked threats use T1543.004.

- [CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…](https://intel.threadlinqs.com/threat/TL-2026-2536) — high — 2026-09-16
- [Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and…](https://intel.threadlinqs.com/threat/TL-2026-2522) — critical — 2026-09-15
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — high — 2026-08-29
- [Post-DEF CON Phishing Campaign Abuses Google Apps Script Sidebar to Deliver AMOS Stealer and NetSupport RAT](https://intel.threadlinqs.com/threat/TL-2026-2449) — high — 2026-08-19
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…](https://intel.threadlinqs.com/threat/TL-2026-1899) — high — 2026-08-05
- [macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…](https://intel.threadlinqs.com/threat/TL-2026-1894) — high — 2026-08-05
- [Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Command](https://intel.threadlinqs.com/threat/TL-2026-1813) — medium — 2026-08-02
- [XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…](https://intel.threadlinqs.com/threat/TL-2026-1792) — high — 2026-07-31
- [EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contract](https://intel.threadlinqs.com/threat/TL-2026-1670) — high — 2026-07-24
- [macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain…](https://intel.threadlinqs.com/threat/TL-2026-1424) — high — 2026-07-16
- [macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…](https://intel.threadlinqs.com/threat/TL-2026-0923) — high — 2026-06-23
- [ClickFix macOS Trio: Loader/Script/Helper Campaigns Deliver SHub Stealer, AMOS, and Macsync Stealer with…](https://intel.threadlinqs.com/threat/TL-2026-0471) — high — 2026-05-06

## Related CVEs

CVEs referenced by the tracked threats that use T1543.004, most frequent first.

- [CVE-2026-43760](https://intel.threadlinqs.com/cve/CVE-2026-43760)
- [CVE-2026-65400](https://intel.threadlinqs.com/cve/CVE-2026-65400)
- [CVE-2026-65414](https://intel.threadlinqs.com/cve/CVE-2026-65414)
- [CVE-2026-90894](https://intel.threadlinqs.com/cve/CVE-2026-90894)

## Detection coverage

Threadlinqs maintains 35 detection rules mapped to T1543.004 (SPL 15, KQL 7, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.

35 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1543 Create or Modify System Process](https://intel.threadlinqs.com/technique/T1543) — 232 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1543.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
