Activity timeline
T1559 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-02 with 13 reports, and 41 of the 41 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1559 Inter-Process Communication is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 12 critical, 26 high, 2 medium.
Threats that use T1559 most often also use T1059 Command and Scripting Interpreter (30 threats), T1082 System Information Discovery (30 threats), T1041 Exfiltration Over C2 Channel (27 threats), T1005 Data from Local System (26 threats), T1027 Obfuscated Files or Information (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
15 tracked threat actors appear in the threats that use T1559; the most frequent are APT28 (3), Forest Blizzard (3), APT29 (1), APT32 (1), BlackSuit affiliate (1).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1559.
Data sources
Telemetry that can reveal T1559, per MITRE ATT&CK.
- Module — Module Load
- Process — Process Access, Process Creation
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 41 tracked threats that use T1559.
- GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking…medium
- CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…high
- CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…high
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…critical
- npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for…critical
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2high
- SentinelLabs Benchmark: Frontier LLMs Attempt Autonomous Long-Horizon Malware Analysis Using the 2005…
- F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition…high
- Fake AI Tool Attacks on SMBs: 33,300 Cyberattacks Masquerading as ChatGPT, Copilot, Claude in Early 2026critical
- Amazon Q Developer Extension Trust-Boundary & Symlink Flaws (CVE-2026-12957, CVE-2026-12958) Auto-Execute…high
- Cloud vn105rkj64 — Italian Invoice Phishing Drops Windows Backdoor and Force-Installed Chrome Extension…high
- AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP…critical
- AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE Vectorhigh
- AutoJack: Single-Page RCE Against Hosts Running AI Agents (AutoGen Studio MCP WebSocket Confused-Deputy Chain)high
- CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection…high
- The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to Deliver ConnectWise ScreenConnect RMM Accesshigh
- OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese…high
- Nimbus RAT (BackupBOX) — Microsoft Teams Vishing + Quick Assist Delivery of a Self-Contained Java RAT Using…high
- Argamal RAT — Trojanized Hentai Games Deliver COM-Hijacking Implant and Downloader for Full Windows System…high
- EKZ Infostealer Campaign — FortiClient EMS CVE-2026-35616 Abused via on_connect Script Injection (Arctic…high
- Kazuar P2P Botnet Evolution — Secret Blizzard (Russia FSB Center 16) Modular Espionage Implant with…high
- UAT-8302 China-Nexus APT Campaign — NetDraft, CloudSorcerer v3, VSHELL/SNOWLIGHT, SNOWRUST…high
- PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation…high
- UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…high
- macOS ClickFix Campaign: AppleScript Stealers Abuse Terminal and Script Editor Before macOS 26 Protectionshigh
- ClickFix macOS Script Editor Pivot — applescript:// Bypass of Tahoe Terminal Paste Warnings Delivers Atomic…high
- CPUID Supply Chain Compromise — Trojanized CPU-Z 2.19, HWMonitor 1.63, PerfMonitor 2, and powerMAX…critical
- Claude Code RCE & API Key Exfiltration — CVE-2025-59536 + CVE-2026-21852, Untrusted Repo Attack Surface via…high
- ClickFix Evolution — nslookup DNS Smuggling + CrashFix Browser DoS + ModeloRAT Python RAT, KongTuke Actor…high
Detection coverage
Threadlinqs maintains 36 detection rules mapped to T1559 (SPL 12, KQL 8, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1559.001 Component Object Model — 10 tracked threats
- T1559.002 Dynamic Data Exchange — 0 tracked threats
- T1559.003 XPC Services — 0 tracked threats