# T1548.003 Sudo and Sudo Caching

> As of 2026-10-05, T1548.003 (Sudo and Sudo Caching) appears in 24 tracked threats, first reported 2026-05-04 and most recently 2026-10-02, with linked actors including TeamPCP; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 24 (7 critical, 15 high, 2 medium)
- **First seen:** 2026-05-04
- **Last seen:** 2026-10-02
- **Threat actors:** 1
- **Detection rules:** 45 (counts only; Blue tier and above)

## Key facts

- **ID:** T1548.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1548
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1548/003/

## Activity timeline

T1548.003 first appeared in tracked threats on 2026-05-04 and was most recently reported on 2026-10-02. The busiest month was 2026-09 with 6 reports, and 24 of the 24 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1548.003 Sudo and Sudo Caching is catalogued by MITRE ATT&CK under the Privilege Escalation tactic in the Enterprise matrix, as a sub-technique of [T1548 Abuse Elevation Control Mechanism](https://intel.threadlinqs.com/technique/T1548). Threadlinqs maps 24 of 2623 tracked threats (0.9%) to it; by severity that is 7 critical, 15 high, 2 medium.

Threats that use T1548.003 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (22 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (14 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (12 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (12 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1548.003; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (3).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1548.003.

- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)

## Data sources

Telemetry that can reveal T1548.003, per MITRE ATT&CK.

- Command — Command Execution
- File — File Modification
- Process — Process Creation, Process Metadata

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3

## Tracked threats

24 tracked threats use T1548.003.

- [CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer](https://intel.threadlinqs.com/threat/TL-2026-2840) — high — 2026-10-02
- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — high — 2026-09-30
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow…](https://intel.threadlinqs.com/threat/TL-2026-2572) — high — 2026-09-18
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2497) — critical — 2026-09-14
- [Multiple Vulnerabilities in Nozomi Guardian/CMC Before 25.4.0 on Siemens RUGGEDCOM APE1808 Devices…](https://intel.threadlinqs.com/threat/TL-2026-2487) — high — 2026-09-13
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — medium — 2026-09-13
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [CVE-2026-43760: macOS Screen Sharing Logic Flaw Allows VNC-Authenticated Root Command Execution](https://intel.threadlinqs.com/threat/TL-2026-2038) — critical — 2026-08-16
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access](https://intel.threadlinqs.com/threat/TL-2026-1925) — critical — 2026-08-07
- [Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)](https://intel.threadlinqs.com/threat/TL-2026-1876) — medium — 2026-08-04
- [SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…](https://intel.threadlinqs.com/threat/TL-2026-1703) — high — 2026-07-26
- [SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machines](https://intel.threadlinqs.com/threat/TL-2026-1575) — high — 2026-07-20
- [SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…](https://intel.threadlinqs.com/threat/TL-2026-1532) — high — 2026-07-19
- [Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1105) — high — 2026-07-05
- [macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…](https://intel.threadlinqs.com/threat/TL-2026-0923) — high — 2026-06-23
- [Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-0979) — critical — 2026-06-12
- [Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm…](https://intel.threadlinqs.com/threat/TL-2026-1234) — high — 2026-06-04
- [LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…](https://intel.threadlinqs.com/threat/TL-2026-0565) — critical — 2026-05-22
- [Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…](https://intel.threadlinqs.com/threat/TL-2026-0547) — critical — 2026-05-21
- [Fragnesia — DirtyFrag-Family Linux Kernel LPE via XFRM ESP-in-TCP Page-Cache Corruption](https://intel.threadlinqs.com/threat/TL-2026-0510) — high — 2026-05-13
- [CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All…](https://intel.threadlinqs.com/threat/TL-2026-0486) — high — 2026-05-08
- [Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…](https://intel.threadlinqs.com/threat/TL-2026-0456) — high — 2026-05-04

## Related CVEs

CVEs referenced by the tracked threats that use T1548.003, most frequent first.

- [CVE-2026-43760](https://intel.threadlinqs.com/cve/CVE-2026-43760)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2026-48172](https://intel.threadlinqs.com/cve/CVE-2026-48172)
- [CVE-2026-65400](https://intel.threadlinqs.com/cve/CVE-2026-65400)
- [CVE-2026-80844](https://intel.threadlinqs.com/cve/CVE-2026-80844)

## Detection coverage

Threadlinqs maintains 45 detection rules mapped to T1548.003 (SPL 12, KQL 15, Sigma 17, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

45 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1548 Abuse Elevation Control Mechanism](https://intel.threadlinqs.com/technique/T1548) — 281 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1548.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
