# T1547.013 XDG Autostart Entries

> As of 2026-10-05, T1547.013 (XDG Autostart Entries) appears in 10 tracked threats, first reported 2026-03-27 and most recently 2026-07-21, with linked actors including APT34, Cavern Manticore, Contagious Interview cluster; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 10 (2 critical, 7 high, 1 medium)
- **First seen:** 2026-03-27
- **Last seen:** 2026-07-21
- **Threat actors:** 5
- **Detection rules:** 12 (counts only; Blue tier and above)

## Key facts

- **ID:** T1547.013
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1547
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1547/013/

## Activity timeline

T1547.013 first appeared in tracked threats on 2026-03-27 and was most recently reported on 2026-07-21. The busiest month was 2026-07 with 7 reports, and 10 of the 10 threats were reported in the twelve months to 2026-07.

## How adversaries use it

T1547.013 XDG Autostart Entries is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1547 Boot or Logon Autostart Execution](https://intel.threadlinqs.com/technique/T1547). Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 2 critical, 7 high, 1 medium.

Threats that use T1547.013 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (9 threats), [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (9 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (8 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (8 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

5 tracked threat actors appear in the threats that use T1547.013; the most frequent are [APT34](https://intel.threadlinqs.com/actor/APT34) (1), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1), [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) (1), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (1), [WageMole](https://intel.threadlinqs.com/actor/WageMole) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1547.013.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)

## Data sources

Telemetry that can reveal T1547.013, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Process — Process Creation

## Threat actors using it

- [APT34](https://intel.threadlinqs.com/actor/APT34) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 1

## Tracked threats

10 tracked threats use T1547.013.

- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…](https://intel.threadlinqs.com/threat/TL-2026-1588) — high — 2026-07-21
- [SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and…](https://intel.threadlinqs.com/threat/TL-2026-1475) — high — 2026-07-18
- [macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain…](https://intel.threadlinqs.com/threat/TL-2026-1424) — high — 2026-07-16
- [ClawHub Marketplace Skills Expose OpenClaw AI Agents to RCE, Data Theft, and Supply-Chain Backdoors…](https://intel.threadlinqs.com/threat/TL-2026-1212) — high — 2026-07-11
- [EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1191) — high — 2026-07-10
- [npm 12 Disables Install Scripts, Git Dependencies, and Remote Tarball URLs by Default to Curb Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-1163) — medium — 2026-07-10
- [PolinRider Campaign: North Korea-Linked Supply Chain Attack Expands Across npm, Packagist, Go Modules, and…](https://intel.threadlinqs.com/threat/TL-2026-1055) — high — 2026-07-01
- [Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…](https://intel.threadlinqs.com/threat/TL-2026-0456) — high — 2026-05-04
- [TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload](https://intel.threadlinqs.com/threat/TL-2026-0304) — critical — 2026-03-31
- [EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interview](https://intel.threadlinqs.com/threat/TL-2026-0293) — critical — 2026-03-27

## Related CVEs

CVEs referenced by the tracked threats that use T1547.013, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)

## Detection coverage

Threadlinqs maintains 12 detection rules mapped to T1547.013 (SPL 4, KQL 5, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

12 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1547 Boot or Logon Autostart Execution](https://intel.threadlinqs.com/technique/T1547) — 349 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1547.013
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
