Activity timeline
T1547.009 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 4 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1547.009 Shortcut Modification is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1547 Boot or Logon Autostart Execution. Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 10 high.
Threats that use T1547.009 most often also use T1204.002 Malicious File (10 threats), T1071.001 Web Protocols (9 threats), T1082 System Information Discovery (9 threats), T1547.001 Registry Run Keys / Startup Folder (9 threats), T1027 Obfuscated Files or Information (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1547.009; the most frequent are APT36 (2), Transparent Tribe (2), Grandoreiro operators (1), LenAI (1), UAT-11795 (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1547.009.
Data sources
Telemetry that can reveal T1547.009, per MITRE ATT&CK.
- File — File Creation, File Modification
- Process — Process Creation
Threat actors using it
Tracked threats
11 tracked threats use T1547.009.
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian…high
- Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRighigh
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver…high
- Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositorieshigh
- Grandoreiro Banking Trojan Resurgence (May 2026) — Dual-Vector DLL Side-Loading & VBS Geofenced Campaign…high
- UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…high
- APT36 "Vibeware" Campaign: AI-Assisted Malware Industrialization Targets Indian and Afghan Governmenthigh
Detection coverage
Threadlinqs maintains 17 detection rules mapped to T1547.009 (SPL 6, KQL 6, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1547 Boot or Logon Autostart Execution — 349 tracked threats at the technique level.