Activity timeline
T1546.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 15 reports, and 28 of the 28 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1546.004 Unix Shell Configuration Modification is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1546 Event Triggered Execution. Threadlinqs maps 28 of 2623 tracked threats (1.1%) to it; by severity that is 10 critical, 18 high.
Threats that use T1546.004 most often also use T1027 Obfuscated Files or Information (21 threats), T1071.001 Web Protocols (20 threats), T1082 System Information Discovery (20 threats), T1005 Data from Local System (19 threats), T1059.004 Unix Shell (17 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1546.004; the most frequent are TeamPCP (5), Shai-Hulud (2), ClickLock Dev (1), Contagious Interview cluster (1), PolinRider (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1546.004.
Data sources
Telemetry that can reveal T1546.004, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Modification
- Process — Process Creation
Threat actors using it
Tracked threats
28 tracked threats use T1546.004.
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host fileshigh
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and…critical
- ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…high
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaignhigh
- ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering…high
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…high
- OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign…high
- ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…high
- AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loadercritical
- "PromptFiction" Claude Desktop Auto-Submit Flaw Chained With "Claudy Day" Claude.ai Exploit Chain Enables…high
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chainhigh
- AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Frameworkcritical
- EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver…high
- Critical Cursor AI Code Editor Flaws (CVE-2026-50548, CVE-2026-50549) — "DuneSlide" Zero-Click Prompt…critical
- Cursor IDE "DuneSlide" Sandbox Escape RCE via Zero-Click Prompt Injection (CVE-2026-50548, CVE-2026-50549)critical
- JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…high
- Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCPcritical
- Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2…high
- Bitwarden CLI 2026.4.0 (@bitwarden/cli) Compromised via Abused GitHub Action in Ongoing Checkmarx Supply…critical
- Telnyx Python SDK PyPI Compromise — TeamPCP CanisterWorm Supply Chain Attack (telnyx 4.87.1/4.87.2)critical
- EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interviewcritical
- TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem…critical
Detection coverage
Threadlinqs maintains 63 detection rules mapped to T1546.004 (SPL 23, KQL 19, Sigma 21). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1546 Event Triggered Execution — 145 tracked threats at the technique level.