# T1546.004 Unix Shell Configuration Modification

> As of 2026-10-05, T1546.004 (Unix Shell Configuration Modification) appears in 28 tracked threats, first reported 2026-03-24 and most recently 2026-09-30, with linked actors including TeamPCP, Shai-Hulud, ClickLock Dev; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 28 (10 critical, 18 high)
- **First seen:** 2026-03-24
- **Last seen:** 2026-09-30
- **Threat actors:** 7
- **Detection rules:** 63 (counts only; Blue tier and above)

## Key facts

- **ID:** T1546.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1546
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1546/004/

## Activity timeline

T1546.004 first appeared in tracked threats on 2026-03-24 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 15 reports, and 28 of the 28 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1546.004 Unix Shell Configuration Modification is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1546 Event Triggered Execution](https://intel.threadlinqs.com/technique/T1546). Threadlinqs maps 28 of 2623 tracked threats (1.1%) to it; by severity that is 10 critical, 18 high.

Threats that use T1546.004 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (21 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (20 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (20 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (19 threats), [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (17 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1546.004; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (5), [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) (2), [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (1), [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) (1), [PolinRider](https://intel.threadlinqs.com/actor/PolinRider) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1546.004.

- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)

## Data sources

Telemetry that can reveal T1546.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Process — Process Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 5
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 2
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) — 1
- [PolinRider](https://intel.threadlinqs.com/actor/PolinRider) — 1
- [UNC5342](https://intel.threadlinqs.com/actor/UNC5342) — 1
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 1

## Tracked threats

28 tracked threats use T1546.004.

- [Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files](https://intel.threadlinqs.com/threat/TL-2026-2812) — high — 2026-09-30
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…](https://intel.threadlinqs.com/threat/TL-2026-2723) — high — 2026-09-27
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor module](https://intel.threadlinqs.com/threat/TL-2026-2641) — high — 2026-09-24
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and…](https://intel.threadlinqs.com/threat/TL-2026-2522) — critical — 2026-09-15
- [ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…](https://intel.threadlinqs.com/threat/TL-2026-1800) — high — 2026-07-31
- [XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…](https://intel.threadlinqs.com/threat/TL-2026-1792) — high — 2026-07-31
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign](https://intel.threadlinqs.com/threat/TL-2026-1570) — high — 2026-07-20
- [ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering…](https://intel.threadlinqs.com/threat/TL-2026-1551) — high — 2026-07-19
- [IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…](https://intel.threadlinqs.com/threat/TL-2026-1477) — high — 2026-07-18
- [OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1441) — high — 2026-07-17
- [ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…](https://intel.threadlinqs.com/threat/TL-2026-1440) — high — 2026-07-17
- [AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loader](https://intel.threadlinqs.com/threat/TL-2026-1387) — critical — 2026-07-15
- ["PromptFiction" Claude Desktop Auto-Submit Flaw Chained With "Claudy Day" Claude.ai Exploit Chain Enables…](https://intel.threadlinqs.com/threat/TL-2026-1380) — high — 2026-07-15
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — high — 2026-07-15
- [AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Framework](https://intel.threadlinqs.com/threat/TL-2026-1360) — critical — 2026-07-15
- [EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1191) — high — 2026-07-10
- [Critical Cursor AI Code Editor Flaws (CVE-2026-50548, CVE-2026-50549) — "DuneSlide" Zero-Click Prompt…](https://intel.threadlinqs.com/threat/TL-2026-1049) — critical — 2026-07-01
- [Cursor IDE "DuneSlide" Sandbox Escape RCE via Zero-Click Prompt Injection (CVE-2026-50548, CVE-2026-50549)](https://intel.threadlinqs.com/threat/TL-2026-1047) — critical — 2026-07-01
- [JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…](https://intel.threadlinqs.com/threat/TL-2026-0490) — high — 2026-05-09
- [Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCP](https://intel.threadlinqs.com/threat/TL-2026-0429) — critical — 2026-04-27
- [Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2…](https://intel.threadlinqs.com/threat/TL-2026-0424) — high — 2026-04-25
- [Bitwarden CLI 2026.4.0 (@bitwarden/cli) Compromised via Abused GitHub Action in Ongoing Checkmarx Supply…](https://intel.threadlinqs.com/threat/TL-2026-0417) — critical — 2026-04-23
- [Telnyx Python SDK PyPI Compromise — TeamPCP CanisterWorm Supply Chain Attack (telnyx 4.87.1/4.87.2)](https://intel.threadlinqs.com/threat/TL-2026-0361) — critical — 2026-04-14
- [EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interview](https://intel.threadlinqs.com/threat/TL-2026-0293) — critical — 2026-03-27
- [TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem…](https://intel.threadlinqs.com/threat/TL-2026-0279) — critical — 2026-03-24

## Related CVEs

CVEs referenced by the tracked threats that use T1546.004, most frequent first.

- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702)
- [CVE-2026-17106](https://intel.threadlinqs.com/cve/CVE-2026-17106)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-43760](https://intel.threadlinqs.com/cve/CVE-2026-43760)
- [CVE-2026-65400](https://intel.threadlinqs.com/cve/CVE-2026-65400)
- [CVE-2026-65414](https://intel.threadlinqs.com/cve/CVE-2026-65414)

## Detection coverage

Threadlinqs maintains 63 detection rules mapped to T1546.004 (SPL 23, KQL 19, Sigma 21). Rule content is available to Blue tier accounts and above; this page shows counts only.

63 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1546 Event Triggered Execution](https://intel.threadlinqs.com/technique/T1546) — 145 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1546.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
