Activity timeline
T1559.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 4 reports, and 10 of the 10 threats were reported in the twelve months to 2026-07.
How adversaries use it
T1559.001 Component Object Model is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1559 Inter-Process Communication. Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 7 high, 2 medium.
Threats that use T1559.001 most often also use T1071.001 Web Protocols (9 threats), T1036.005 Match Legitimate Resource Name or Location (8 threats), T1204.002 Malicious File (8 threats), T1027 Obfuscated Files or Information (7 threats), T1053.005 Scheduled Task (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1559.001; the most frequent are Chaotic Eclipse (1), Gamaredon Group (1), MuddyWater (1), Nightmare Eclipse (1), Payouts King (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1559.001.
Data sources
Telemetry that can reveal T1559.001, per MITRE ATT&CK.
- Module — Module Load
- Process — Process Creation
- Script — Script Execution
Threat actors using it
Tracked threats
10 tracked threats use T1559.001.
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)high
- Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domainshigh
- Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…medium
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- Edgecution: Payouts King Initial Access Broker Deploys Malicious Microsoft Edge Extension with Embedded…high
- Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)high
- Internet Explorer WebBrowser Control Attack Chain — Two-Click RCE via Zone/MOTW Bypass and ActiveX COM…high
- SEO Poisoning Campaign Impersonates Gemini CLI and Claude Code to Deliver In-Memory PowerShell Infostealer…high
- InstallFix Campaign — Fake Claude AI Installer via Google Ads Drops mshta/ZIP-HTA Polyglot, AMSI-Bypass…high
- CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP — Iran MOIS-Linked MuddyWater AI-Assisted Malware…critical
Detection coverage
Threadlinqs maintains 31 detection rules mapped to T1559.001 (SPL 8, KQL 12, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1559 Inter-Process Communication — 41 tracked threats at the technique level.