# T1548.001 Setuid and Setgid

> As of 2026-10-05, T1548.001 (Setuid and Setgid) appears in 26 tracked threats, first reported 2026-02-16 and most recently 2026-09-27, with linked actors including Greatness PhaaS Operators, INC Ransomware, The Gentlemen; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 26 (9 critical, 16 high, 1 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-27
- **Threat actors:** 4
- **Detection rules:** 63 (counts only; Blue tier and above)

## Key facts

- **ID:** T1548.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1548
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1548/001/

## Activity timeline

T1548.001 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 10 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1548.001 Setuid and Setgid is catalogued by MITRE ATT&CK under the Privilege Escalation tactic in the Enterprise matrix, as a sub-technique of [T1548 Abuse Elevation Control Mechanism](https://intel.threadlinqs.com/technique/T1548). Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 9 critical, 16 high, 1 medium.

Threats that use T1548.001 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (21 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (18 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (13 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (13 threats), [T1211 Exploitation for Stealth](https://intel.threadlinqs.com/technique/T1211) (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1548.001; the most frequent are [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) (1), [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) (1), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (1), [UNC5221](https://intel.threadlinqs.com/actor/UNC5221) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1548.001.

- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)

## Data sources

Telemetry that can reveal T1548.001, per MITRE ATT&CK.

- Command — Command Execution
- File — File Metadata, File Modification

## Threat actors using it

- [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) — 1
- [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) — 1
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1
- [UNC5221](https://intel.threadlinqs.com/actor/UNC5221) — 1

## Tracked threats

26 tracked threats use T1548.001.

- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…](https://intel.threadlinqs.com/threat/TL-2026-2514) — high — 2026-09-15
- [SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2497) — critical — 2026-09-14
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — medium — 2026-09-13
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day…](https://intel.threadlinqs.com/threat/TL-2026-2893) — high — 2026-08-06
- [CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of…](https://intel.threadlinqs.com/threat/TL-2026-1831) — high — 2026-08-03
- [SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…](https://intel.threadlinqs.com/threat/TL-2026-1703) — high — 2026-07-26
- [CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root](https://intel.threadlinqs.com/threat/TL-2026-1633) — high — 2026-07-22
- [SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machines](https://intel.threadlinqs.com/threat/TL-2026-1575) — high — 2026-07-20
- [SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…](https://intel.threadlinqs.com/threat/TL-2026-1532) — high — 2026-07-19
- [IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…](https://intel.threadlinqs.com/threat/TL-2026-1477) — high — 2026-07-18
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…](https://intel.threadlinqs.com/threat/TL-2026-1463) — critical — 2026-07-17
- [SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1462) — critical — 2026-07-17
- [Linux Kernel FUSE Page-Cache Buffer Overflow (CVE-2026-31694) Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1177) — high — 2026-07-10
- [JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…](https://intel.threadlinqs.com/threat/TL-2026-1142) — high — 2026-07-06
- [Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1105) — high — 2026-07-05
- [Linux Kernel LPE Surge: Copy Fail (CVE-2026-31431), Dirty Frag/Fragnesia…](https://intel.threadlinqs.com/threat/TL-2026-2424) — high — 2026-05-29
- [LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…](https://intel.threadlinqs.com/threat/TL-2026-0565) — critical — 2026-05-22
- [Fragnesia — DirtyFrag-Family Linux Kernel LPE via XFRM ESP-in-TCP Page-Cache Corruption](https://intel.threadlinqs.com/threat/TL-2026-0510) — high — 2026-05-13
- [JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…](https://intel.threadlinqs.com/threat/TL-2026-0490) — high — 2026-05-09
- [CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All…](https://intel.threadlinqs.com/threat/TL-2026-0486) — high — 2026-05-08
- [Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE…](https://intel.threadlinqs.com/threat/TL-2026-0483) — critical — 2026-05-08
- [Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch…](https://intel.threadlinqs.com/threat/TL-2026-0121) — critical — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1548.001, most frequent first.

- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702)
- [CVE-2026-1281](https://intel.threadlinqs.com/cve/CVE-2026-1281)
- [CVE-2026-1340](https://intel.threadlinqs.com/cve/CVE-2026-1340)
- [CVE-2026-31694](https://intel.threadlinqs.com/cve/CVE-2026-31694)
- [CVE-2026-43284](https://intel.threadlinqs.com/cve/CVE-2026-43284)
- [CVE-2026-43500](https://intel.threadlinqs.com/cve/CVE-2026-43500)
- [CVE-2026-48172](https://intel.threadlinqs.com/cve/CVE-2026-48172)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-88773](https://intel.threadlinqs.com/cve/CVE-2026-88773)
- [CVE-2026-88774](https://intel.threadlinqs.com/cve/CVE-2026-88774)
- [CVE-2026-88775](https://intel.threadlinqs.com/cve/CVE-2026-88775)
- [CVE-2026-88776](https://intel.threadlinqs.com/cve/CVE-2026-88776)
- [CVE-2026-88777](https://intel.threadlinqs.com/cve/CVE-2026-88777)
- [CVE-2026-88778](https://intel.threadlinqs.com/cve/CVE-2026-88778)
- [CVE-2026-8933](https://intel.threadlinqs.com/cve/CVE-2026-8933)

## Detection coverage

Threadlinqs maintains 63 detection rules mapped to T1548.001 (SPL 22, KQL 19, Sigma 19, other 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

63 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1548 Abuse Elevation Control Mechanism](https://intel.threadlinqs.com/technique/T1548) — 281 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1548.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
