# T1546 Event Triggered Execution

> As of 2026-10-05, T1546 (Event Triggered Execution) appears in 145 tracked threats, first reported 2026-02-02 and most recently 2026-09-26, with linked actors including TeamPCP, Contagious Interview, APT28; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 145 (55 critical, 80 high, 9 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-26
- **Threat actors:** 41
- **Detection rules:** 135 (counts only; Blue tier and above)

## Key facts

- **ID:** T1546
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1546/

## Activity timeline

T1546 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-26. The busiest month was 2026-07 with 33 reports, and 145 of the 145 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1546 Event Triggered Execution is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix. Threadlinqs maps 145 of 2623 tracked threats (5.5%) to it; by severity that is 55 critical, 80 high, 9 medium.

Threats that use T1546 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (100 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (98 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (95 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (88 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (86 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

41 tracked threat actors appear in the threats that use T1546; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (20), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (8), [APT28](https://intel.threadlinqs.com/actor/APT28) (6), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (6), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (6).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1546.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1546, per MITRE ATT&CK.

- Cloud Service — Cloud Service Modification
- Command — Command Execution
- File — File Creation, File Metadata, File Modification
- Module — Module Load
- Process — Process Creation
- WMI — WMI Creation
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 20
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 8
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 6
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 6
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 5
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 5
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 4
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 4
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 4
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 3

## Tracked threats

The 30 most recent of 145 tracked threats that use T1546.

- [CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…](https://intel.threadlinqs.com/threat/TL-2026-2678) — critical — 2026-09-26
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — critical — 2026-09-18
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception](https://intel.threadlinqs.com/threat/TL-2026-2294) — high — 2026-09-02
- [Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync…](https://intel.threadlinqs.com/threat/TL-2026-2241) — high — 2026-08-30
- [CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host…](https://intel.threadlinqs.com/threat/TL-2026-2220) — high — 2026-08-29
- [SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targeting](https://intel.threadlinqs.com/threat/TL-2026-2104) — high — 2026-08-21
- [Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813)](https://intel.threadlinqs.com/threat/TL-2026-2092) — critical — 2026-08-20
- [CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…](https://intel.threadlinqs.com/threat/TL-2026-2087) — critical — 2026-08-20
- [CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access](https://intel.threadlinqs.com/threat/TL-2026-1925) — critical — 2026-08-07
- ['ChainDrop' self-propagating worm compromises hundreds of popular npm packages (keyv, cacheable ecosystem)…](https://intel.threadlinqs.com/threat/TL-2026-2822) — critical — 2026-08-04
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale](https://intel.threadlinqs.com/threat/TL-2026-1867) — medium — 2026-08-04
- [npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for…](https://intel.threadlinqs.com/threat/TL-2026-1866) — critical — 2026-08-04
- [NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825…](https://intel.threadlinqs.com/threat/TL-2026-1865) — critical — 2026-08-04
- [QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator](https://intel.threadlinqs.com/threat/TL-2026-1864) — medium — 2026-08-04
- [Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via…](https://intel.threadlinqs.com/threat/TL-2026-1863) — critical — 2026-08-04
- [Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)](https://intel.threadlinqs.com/threat/TL-2026-1861) — critical — 2026-08-04
- [Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-1860) — critical — 2026-08-04
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and…](https://intel.threadlinqs.com/threat/TL-2026-1839) — critical — 2026-08-03
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for…](https://intel.threadlinqs.com/threat/TL-2026-1838) — critical — 2026-08-03
- [North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…](https://intel.threadlinqs.com/threat/TL-2026-1794) — high — 2026-07-31
- [Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)](https://intel.threadlinqs.com/threat/TL-2026-1767) — critical — 2026-07-29
- [AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups](https://intel.threadlinqs.com/threat/TL-2026-1761) — medium — 2026-07-29
- [US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…](https://intel.threadlinqs.com/threat/TL-2026-1751) — high — 2026-07-29
- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://intel.threadlinqs.com/threat/TL-2026-1745) — high — 2026-07-28

## Related CVEs

CVEs referenced by the tracked threats that use T1546, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2024-3094](https://intel.threadlinqs.com/cve/CVE-2024-3094)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2026-94127](https://intel.threadlinqs.com/cve/CVE-2026-94127)
- [CVE-2017-6742](https://intel.threadlinqs.com/cve/CVE-2017-6742)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-36899](https://intel.threadlinqs.com/cve/CVE-2023-36899)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2024-11182](https://intel.threadlinqs.com/cve/CVE-2024-11182)
- [CVE-2024-27443](https://intel.threadlinqs.com/cve/CVE-2024-27443)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)

## Detection coverage

Threadlinqs maintains 135 detection rules mapped to T1546 (SPL 51, KQL 44, Sigma 38, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

135 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1546.001 Change Default File Association — 4 tracked threats
- T1546.002 Screensaver — 1 tracked threat
- T1546.003 Windows Management Instrumentation Event Subscription — 8 tracked threats
- [T1546.004 Unix Shell Configuration Modification](https://intel.threadlinqs.com/technique/T1546.004) — 28 tracked threats
- T1546.005 Trap — 0 tracked threats
- T1546.006 LC_LOAD_DYLIB Addition — 0 tracked threats
- T1546.007 Netsh Helper DLL — 0 tracked threats
- T1546.008 Accessibility Features — 1 tracked threat
- T1546.009 AppCert DLLs — 0 tracked threats
- T1546.010 AppInit DLLs — 0 tracked threats
- T1546.011 Application Shimming — 1 tracked threat
- T1546.012 Image File Execution Options Injection — 1 tracked threat
- T1546.013 PowerShell Profile — 2 tracked threats
- T1546.014 Emond — 1 tracked threat
- [T1546.015 Component Object Model Hijacking](https://intel.threadlinqs.com/technique/T1546.015) — 15 tracked threats
- T1546.016 Installer Packages — 5 tracked threats
- T1546.017 Udev Rules — 1 tracked threat
- T1546.018 Python Startup Hooks — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1546
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
