# T1547.009 Shortcut Modification

> As of 2026-10-05, T1547.009 (Shortcut Modification) appears in 11 tracked threats, first reported 2026-03-05 and most recently 2026-09-25, with linked actors including APT36, Transparent Tribe, Grandoreiro operators; it most often appears alongside T1204.002 (Malicious File).

- **Tracked threats:** 11 (1 critical, 10 high)
- **First seen:** 2026-03-05
- **Last seen:** 2026-09-25
- **Threat actors:** 6
- **Detection rules:** 17 (counts only; Blue tier and above)

## Key facts

- **ID:** T1547.009
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1547
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1547/009/

## Activity timeline

T1547.009 first appeared in tracked threats on 2026-03-05 and was most recently reported on 2026-09-25. The busiest month was 2026-07 with 4 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1547.009 Shortcut Modification is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1547 Boot or Logon Autostart Execution](https://intel.threadlinqs.com/technique/T1547). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 10 high.

Threats that use T1547.009 most often also use [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (10 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (9 threats), [T1547.001 Registry Run Keys / Startup Folder](https://intel.threadlinqs.com/technique/T1547.001) (9 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1547.009; the most frequent are [APT36](https://intel.threadlinqs.com/actor/APT36) (2), [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) (2), [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) (1), [LenAI](https://intel.threadlinqs.com/actor/LenAI) (1), [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1547.009.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)

## Data sources

Telemetry that can reveal T1547.009, per MITRE ATT&CK.

- File — File Creation, File Modification
- Process — Process Creation

## Threat actors using it

- [APT36](https://intel.threadlinqs.com/actor/APT36) — 2
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 2
- [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 1
- [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) — 1

## Tracked threats

11 tracked threats use T1547.009.

- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian…](https://intel.threadlinqs.com/threat/TL-2026-2006) — high — 2026-08-13
- [Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig](https://intel.threadlinqs.com/threat/TL-2026-1979) — high — 2026-08-10
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1454) — high — 2026-07-17
- [Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositories](https://intel.threadlinqs.com/threat/TL-2026-1307) — high — 2026-07-14
- [Grandoreiro Banking Trojan Resurgence (May 2026) — Dual-Vector DLL Side-Loading & VBS Geofenced Campaign…](https://intel.threadlinqs.com/threat/TL-2026-0609) — high — 2026-05-27
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [APT36 "Vibeware" Campaign: AI-Assisted Malware Industrialization Targets Indian and Afghan Government](https://intel.threadlinqs.com/threat/TL-2026-2123) — high — 2026-03-05

## Related CVEs

CVEs referenced by the tracked threats that use T1547.009, most frequent first.

- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)

## Detection coverage

Threadlinqs maintains 17 detection rules mapped to T1547.009 (SPL 6, KQL 6, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

17 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1547 Boot or Logon Autostart Execution](https://intel.threadlinqs.com/technique/T1547) — 349 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1547.009
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
