Activity timeline
T1548 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 113 reports, and 281 of the 281 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1548 Abuse Elevation Control Mechanism is catalogued by MITRE ATT&CK under the Privilege Escalation tactic in the Enterprise matrix. Threadlinqs maps 281 of 2623 tracked threats (10.7%) to it; by severity that is 115 critical, 152 high, 13 medium.
Threats that use T1548 most often also use T1059 Command and Scripting Interpreter (190 threats), T1005 Data from Local System (161 threats), T1082 System Information Discovery (159 threats), T1071 Application Layer Protocol (134 threats), T1685 Disable or Modify Tools (134 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
54 tracked threat actors appear in the threats that use T1548; the most frequent are Nightmare Eclipse (5), TeamPCP (5), APT38 (4), Chaotic Eclipse (4), Black Basta (3).
Mitigations
MITRE ATT&CK lists 8 mitigations for T1548.
Data sources
Telemetry that can reveal T1548, per MITRE ATT&CK.
- Command — Command Execution
- File — File Metadata, File Modification
- Process — OS API Execution, Process Creation, Process Metadata
- User Account — User Account Modification
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 281 tracked threats that use T1548.
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…critical
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…high
- CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Pluginhigh
- DeepSeek Harness Authentication Bypass Lets Sandboxed AI Agents Escape via Single Command (CVE-2026-82533)critical
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…high
- HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege…medium
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malwarehigh
- ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs…critical
- CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…high
- CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…critical
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)high
- Oracle August 2026 CSPU: Nine Vulnerabilities in Agile Engineering Data Management 6.2.1, Including…critical
- MacSync Stealer: Malvertising Campaign Impersonates Claude/Apple Support to Deploy macOS Infostealerhigh
- OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio…high
- DeadLock Ransomware: Rust-Based Encryptor with Decentralized Recovery Infrastructure on Polygon and Sessionhigh
- Odysseus AI Workspace Remote Code Execution via Authorization Bypass — GHSA-xwhc-f36c-v5vm (CVSS 9.9)critical
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…high
- Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser…high
- Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…critical
- Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via…critical
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege…high
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via…critical
- Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authenticationcritical
- XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and…critical
- CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for…critical
Detection coverage
Threadlinqs maintains 235 detection rules mapped to T1548 (SPL 78, KQL 86, Sigma 69, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1548.001 Setuid and Setgid — 26 tracked threats
- T1548.002 Bypass User Account Control — 78 tracked threats
- T1548.003 Sudo and Sudo Caching — 24 tracked threats
- T1548.004 Elevated Execution with Prompt — 6 tracked threats
- T1548.005 Temporary Elevated Cloud Access — 1 tracked threat
- T1548.006 TCC Manipulation — 3 tracked threats