# T1543 Create or Modify System Process

> As of 2026-10-05, T1543 (Create or Modify System Process) appears in 232 tracked threats, first reported 2026-02-02 and most recently 2026-09-19, with linked actors including TeamPCP, APT38, Stardust Chollima; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 232 (97 critical, 121 high, 12 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-19
- **Threat actors:** 69
- **Detection rules:** 68 (counts only; Blue tier and above)

## Key facts

- **ID:** T1543
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1543/

## Activity timeline

T1543 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-19. The busiest month was 2026-07 with 65 reports, and 232 of the 232 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1543 Create or Modify System Process is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix. Threadlinqs maps 232 of 2623 tracked threats (8.8%) to it; by severity that is 97 critical, 121 high, 12 medium.

Threats that use T1543 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (193 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (165 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (161 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (155 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (149 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

69 tracked threat actors appear in the threats that use T1543; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (14), [APT38](https://intel.threadlinqs.com/actor/APT38) (7), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (6), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (5), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (5).

## Mitigations

MITRE ATT&CK lists 9 mitigations for T1543.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1543, per MITRE ATT&CK.

- Command — Command Execution
- Container — Container Creation
- Driver — Driver Load
- File — File Creation, File Modification
- Process — OS API Execution, Process Creation
- Service — Service Creation, Service Modification
- Windows Registry — Windows Registry Key Creation, Windows Registry Key Modification

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 14
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 7
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 6
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 5
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 5
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 5
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 4
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 4
- [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) — 3
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 3
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 3
- [UNC5221](https://intel.threadlinqs.com/actor/UNC5221) — 3

## Tracked threats

The 30 most recent of 232 tracked threats that use T1543.

- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — critical — 2026-09-19
- [CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…](https://intel.threadlinqs.com/threat/TL-2026-2536) — high — 2026-09-16
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security](https://intel.threadlinqs.com/threat/TL-2026-2434) — high — 2026-09-10
- [CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-2415) — critical — 2026-09-09
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)](https://intel.threadlinqs.com/threat/TL-2026-2182) — high — 2026-08-28
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — high — 2026-08-21
- [SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2090) — critical — 2026-08-20
- [Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…](https://intel.threadlinqs.com/threat/TL-2026-2089) — critical — 2026-08-20
- [CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…](https://intel.threadlinqs.com/threat/TL-2026-2087) — critical — 2026-08-20
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [MacSync Stealer: Malvertising Campaign Impersonates Claude/Apple Support to Deploy macOS Infostealer](https://intel.threadlinqs.com/threat/TL-2026-2061) — high — 2026-08-17
- [TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bank](https://intel.threadlinqs.com/threat/TL-2026-1977) — high — 2026-08-10
- [CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access](https://intel.threadlinqs.com/threat/TL-2026-1925) — critical — 2026-08-07
- [Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…](https://intel.threadlinqs.com/threat/TL-2026-1918) — high — 2026-08-06
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…](https://intel.threadlinqs.com/threat/TL-2026-1917) — high — 2026-08-06
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code…](https://intel.threadlinqs.com/threat/TL-2026-1893) — critical — 2026-08-05
- [CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted…](https://intel.threadlinqs.com/threat/TL-2026-1885) — high — 2026-08-05
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projects](https://intel.threadlinqs.com/threat/TL-2026-1870) — high — 2026-08-04
- [AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale](https://intel.threadlinqs.com/threat/TL-2026-1867) — medium — 2026-08-04
- [Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via…](https://intel.threadlinqs.com/threat/TL-2026-1863) — critical — 2026-08-04
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and…](https://intel.threadlinqs.com/threat/TL-2026-1839) — critical — 2026-08-03
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for…](https://intel.threadlinqs.com/threat/TL-2026-1838) — critical — 2026-08-03

## Related CVEs

CVEs referenced by the tracked threats that use T1543, most frequent first.

- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-21514](https://intel.threadlinqs.com/cve/CVE-2026-21514)
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519)

## Detection coverage

Threadlinqs maintains 68 detection rules mapped to T1543 (SPL 21, KQL 22, Sigma 25). Rule content is available to Blue tier accounts and above; this page shows counts only.

68 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1543.001 Launch Agent](https://intel.threadlinqs.com/technique/T1543.001) — 57 tracked threats
- [T1543.002 Systemd Service](https://intel.threadlinqs.com/technique/T1543.002) — 49 tracked threats
- [T1543.003 Windows Service](https://intel.threadlinqs.com/technique/T1543.003) — 78 tracked threats
- [T1543.004 Launch Daemon](https://intel.threadlinqs.com/technique/T1543.004) — 14 tracked threats
- T1543.005 Container Service — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1543
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
