Activity timeline
T1548.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 10 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1548.001 Setuid and Setgid is catalogued by MITRE ATT&CK under the Privilege Escalation tactic in the Enterprise matrix, as a sub-technique of T1548 Abuse Elevation Control Mechanism. Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 9 critical, 16 high, 1 medium.
Threats that use T1548.001 most often also use T1059.004 Unix Shell (21 threats), T1082 System Information Discovery (18 threats), T1068 Exploitation for Privilege Escalation (13 threats), T1071.001 Web Protocols (13 threats), T1211 Exploitation for Stealth (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use T1548.001; the most frequent are Greatness PhaaS Operators (1), INC Ransomware (1), The Gentlemen (1), UNC5221 (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1548.001.
Data sources
Telemetry that can reveal T1548.001, per MITRE ATT&CK.
- Command — Command Execution
- File — File Metadata, File Modification
Threat actors using it
Tracked threats
26 tracked threats use T1548.001.
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitationcritical
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…high
- SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoorcritical
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injectionmedium
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day…high
- CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of…high
- SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…high
- CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Roothigh
- SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machineshigh
- SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…high
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…high
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…critical
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…critical
- Linux Kernel FUSE Page-Cache Buffer Overflow (CVE-2026-31694) Enables Local Privilege Escalationhigh
- JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…high
- Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege…high
- Linux Kernel LPE Surge: Copy Fail (CVE-2026-31431), Dirty Frag/Fragnesia…high
- LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…critical
- Fragnesia — DirtyFrag-Family Linux Kernel LPE via XFRM ESP-in-TCP Page-Cache Corruptionhigh
- JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…high
- CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All…high
- Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE…critical
- Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch…critical
Detection coverage
Threadlinqs maintains 63 detection rules mapped to T1548.001 (SPL 22, KQL 19, Sigma 19, other 3). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1548 Abuse Elevation Control Mechanism — 281 tracked threats at the technique level.