Activity timeline
T1546.015 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1546.015 Component Object Model Hijacking is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1546 Event Triggered Execution. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 4 critical, 10 high, 1 medium.
Threats that use T1546.015 most often also use T1071.001 Web Protocols (10 threats), T1204.002 Malicious File (9 threats), T1036.005 Match Legitimate Resource Name or Location (8 threats), T1082 System Information Discovery (8 threats), T1140 Deobfuscate/Decode Files or Information (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
28 tracked threat actors appear in the threats that use T1546.015; the most frequent are APT-C-60 (2), Head Mare (2), APT10 (1), APT28 (1), APT32 (1).
Data sources
Telemetry that can reveal T1546.015, per MITRE ATT&CK.
- Command — Command Execution
- Module — Module Load
- Process — Process Creation
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
15 tracked threats use T1546.015.
- CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user…high
- APT-C-60 Spear-Phishing Campaign Against Japanese Recruiters Using VHDX/LNK and SpyGlace Malwarehigh
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…critical
- Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoorscritical
- CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaignhigh
- LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…high
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…high
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain…medium
- SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr…high
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as…high
- Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…high
- OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relayhigh
- CPUID Supply Chain Compromise — Trojanized CPU-Z 2.19, HWMonitor 1.63, PerfMonitor 2, and powerMAX…critical
- Malicious NuGet Packages — JIT Hooking ASP.NET Identity Exfiltration and Persistent Backdoor via Local Proxy…high
- RomCom & Paper Werewolf Exploiting WinRAR CVE-2025-8088 Zero-Day via ADS Path Traversalcritical
Detection coverage
Threadlinqs maintains 51 detection rules mapped to T1546.015 (SPL 22, KQL 18, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1546 Event Triggered Execution — 145 tracked threats at the technique level.