# T1559.001 Component Object Model

> As of 2026-10-05, T1559.001 (Component Object Model) appears in 10 tracked threats, first reported 2026-03-01 and most recently 2026-07-23, with linked actors including Chaotic Eclipse, Gamaredon Group, MuddyWater; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 10 (1 critical, 7 high, 2 medium)
- **First seen:** 2026-03-01
- **Last seen:** 2026-07-23
- **Threat actors:** 8
- **Detection rules:** 31 (counts only; Blue tier and above)

## Key facts

- **ID:** T1559.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Parent:** T1559
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1559/001/

## Activity timeline

T1559.001 first appeared in tracked threats on 2026-03-01 and was most recently reported on 2026-07-23. The busiest month was 2026-07 with 4 reports, and 10 of the 10 threats were reported in the twelve months to 2026-07.

## How adversaries use it

T1559.001 Component Object Model is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of [T1559 Inter-Process Communication](https://intel.threadlinqs.com/technique/T1559). Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 7 high, 2 medium.

Threats that use T1559.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (8 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (8 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (7 threats), [T1053.005 Scheduled Task](https://intel.threadlinqs.com/technique/T1053.005) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1559.001; the most frequent are [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (1), [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) (1), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (1), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (1), [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1559.001.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1048 Application Isolation and Sandboxing](https://attack.mitre.org/mitigations/M1048/)

## Data sources

Telemetry that can reveal T1559.001, per MITRE ATT&CK.

- Module — Module Load
- Process — Process Creation
- Script — Script Execution

## Threat actors using it

- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 1
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 1
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 1
- [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) — 1
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 1

## Tracked threats

10 tracked threats use T1559.001.

- [TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)](https://intel.threadlinqs.com/threat/TL-2026-1651) — high — 2026-07-23
- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Edgecution: Payouts King Initial Access Broker Deploys Malicious Microsoft Edge Extension with Embedded…](https://intel.threadlinqs.com/threat/TL-2026-0917) — high — 2026-06-23
- [Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)](https://intel.threadlinqs.com/threat/TL-2026-0743) — high — 2026-06-10
- [Internet Explorer WebBrowser Control Attack Chain — Two-Click RCE via Zone/MOTW Bypass and ActiveX COM…](https://intel.threadlinqs.com/threat/TL-2026-0715) — high — 2026-06-08
- [SEO Poisoning Campaign Impersonates Gemini CLI and Claude Code to Deliver In-Memory PowerShell Infostealer…](https://intel.threadlinqs.com/threat/TL-2026-0546) — high — 2026-05-21
- [InstallFix Campaign — Fake Claude AI Installer via Google Ads Drops mshta/ZIP-HTA Polyglot, AMSI-Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0463) — high — 2026-05-05
- [CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP — Iran MOIS-Linked MuddyWater AI-Assisted Malware…](https://intel.threadlinqs.com/threat/TL-2026-0160) — critical — 2026-03-01

## Detection coverage

Threadlinqs maintains 31 detection rules mapped to T1559.001 (SPL 8, KQL 12, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

31 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1559 Inter-Process Communication](https://intel.threadlinqs.com/technique/T1559) — 41 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1559.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
