# T1559 Inter-Process Communication

> As of 2026-10-05, T1559 (Inter-Process Communication) appears in 41 tracked threats, first reported 2026-02-02 and most recently 2026-09-28, with linked actors including APT28, Forest Blizzard, APT29; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 41 (12 critical, 26 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-28
- **Threat actors:** 15
- **Detection rules:** 36 (counts only; Blue tier and above)

## Key facts

- **ID:** T1559
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1559/

## Activity timeline

T1559 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-28. The busiest month was 2026-02 with 13 reports, and 41 of the 41 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1559 Inter-Process Communication is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 12 critical, 26 high, 2 medium.

Threats that use T1559 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (30 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (30 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (27 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (26 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

15 tracked threat actors appear in the threats that use T1559; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (3), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (3), [APT29](https://intel.threadlinqs.com/actor/APT29) (1), [APT32](https://intel.threadlinqs.com/actor/APT32) (1), [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) (1).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1559.

- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)
- [M1048 Application Isolation and Sandboxing](https://attack.mitre.org/mitigations/M1048/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1559, per MITRE ATT&CK.

- Module — Module Load
- Process — Process Access, Process Creation
- Script — Script Execution

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 3
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 1
- [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 1
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 1
- [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 1

## Tracked threats

The 30 most recent of 41 tracked threats that use T1559.

- [GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking…](https://intel.threadlinqs.com/threat/TL-2026-2744) — medium — 2026-09-28
- [CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…](https://intel.threadlinqs.com/threat/TL-2026-2536) — high — 2026-09-16
- [CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…](https://intel.threadlinqs.com/threat/TL-2026-2479) — high — 2026-09-13
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1901) — critical — 2026-08-05
- [npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for…](https://intel.threadlinqs.com/threat/TL-2026-1866) — critical — 2026-08-04
- [TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2](https://intel.threadlinqs.com/threat/TL-2026-1684) — high — 2026-07-23
- [SentinelLabs Benchmark: Frontier LLMs Attempt Autonomous Long-Horizon Malware Analysis Using the 2005…](https://intel.threadlinqs.com/threat/TL-2026-1630) — 2026-07-22
- [F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition…](https://intel.threadlinqs.com/threat/TL-2026-1503) — high — 2026-07-18
- [Fake AI Tool Attacks on SMBs: 33,300 Cyberattacks Masquerading as ChatGPT, Copilot, Claude in Early 2026](https://intel.threadlinqs.com/threat/TL-2026-0993) — critical — 2026-06-28
- [Amazon Q Developer Extension Trust-Boundary & Symlink Flaws (CVE-2026-12957, CVE-2026-12958) Auto-Execute…](https://intel.threadlinqs.com/threat/TL-2026-0950) — high — 2026-06-26
- [Cloud vn105rkj64 — Italian Invoice Phishing Drops Windows Backdoor and Force-Installed Chrome Extension…](https://intel.threadlinqs.com/threat/TL-2026-0948) — high — 2026-06-26
- [AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP…](https://intel.threadlinqs.com/threat/TL-2026-0883) — critical — 2026-06-19
- [AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE Vector](https://intel.threadlinqs.com/threat/TL-2026-0873) — high — 2026-06-19
- [AutoJack: Single-Page RCE Against Hosts Running AI Agents (AutoGen Studio MCP WebSocket Confused-Deputy Chain)](https://intel.threadlinqs.com/threat/TL-2026-0862) — high — 2026-06-18
- [CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection…](https://intel.threadlinqs.com/threat/TL-2026-0835) — high — 2026-06-17
- [The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to Deliver ConnectWise ScreenConnect RMM Access](https://intel.threadlinqs.com/threat/TL-2026-0805) — high — 2026-06-15
- [OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese…](https://intel.threadlinqs.com/threat/TL-2026-0795) — high — 2026-06-14
- [Nimbus RAT (BackupBOX) — Microsoft Teams Vishing + Quick Assist Delivery of a Self-Contained Java RAT Using…](https://intel.threadlinqs.com/threat/TL-2026-0691) — high — 2026-06-06
- [Argamal RAT — Trojanized Hentai Games Deliver COM-Hijacking Implant and Downloader for Full Windows System…](https://intel.threadlinqs.com/threat/TL-2026-0670) — high — 2026-06-03
- [EKZ Infostealer Campaign — FortiClient EMS CVE-2026-35616 Abused via on_connect Script Injection (Arctic…](https://intel.threadlinqs.com/threat/TL-2026-0611) — high — 2026-05-27
- [Kazuar P2P Botnet Evolution — Secret Blizzard (Russia FSB Center 16) Modular Espionage Implant with…](https://intel.threadlinqs.com/threat/TL-2026-0519) — high — 2026-05-16
- [UAT-8302 China-Nexus APT Campaign — NetDraft, CloudSorcerer v3, VSHELL/SNOWLIGHT, SNOWRUST…](https://intel.threadlinqs.com/threat/TL-2026-0462) — high — 2026-05-05
- [PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation…](https://intel.threadlinqs.com/threat/TL-2026-0420) — high — 2026-04-24
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [macOS ClickFix Campaign: AppleScript Stealers Abuse Terminal and Script Editor Before macOS 26 Protections](https://intel.threadlinqs.com/threat/TL-2026-0396) — high — 2026-04-20
- [ClickFix macOS Script Editor Pivot — applescript:// Bypass of Tahoe Terminal Paste Warnings Delivers Atomic…](https://intel.threadlinqs.com/threat/TL-2026-0348) — high — 2026-04-10
- [CPUID Supply Chain Compromise — Trojanized CPU-Z 2.19, HWMonitor 1.63, PerfMonitor 2, and powerMAX…](https://intel.threadlinqs.com/threat/TL-2026-0347) — critical — 2026-04-10
- [Claude Code RCE & API Key Exfiltration — CVE-2025-59536 + CVE-2026-21852, Untrusted Repo Attack Surface via…](https://intel.threadlinqs.com/threat/TL-2026-0146) — high — 2026-02-26
- [ClickFix Evolution — nslookup DNS Smuggling + CrashFix Browser DoS + ModeloRAT Python RAT, KongTuke Actor…](https://intel.threadlinqs.com/threat/TL-2026-0118) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1559, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-21514](https://intel.threadlinqs.com/cve/CVE-2026-21514)
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519)
- [CVE-2026-21522](https://intel.threadlinqs.com/cve/CVE-2026-21522)
- [CVE-2026-21525](https://intel.threadlinqs.com/cve/CVE-2026-21525)
- [CVE-2026-21532](https://intel.threadlinqs.com/cve/CVE-2026-21532)
- [CVE-2026-21533](https://intel.threadlinqs.com/cve/CVE-2026-21533)
- [CVE-2026-23655](https://intel.threadlinqs.com/cve/CVE-2026-23655)
- [CVE-2026-24300](https://intel.threadlinqs.com/cve/CVE-2026-24300)
- [CVE-2026-24302](https://intel.threadlinqs.com/cve/CVE-2026-24302)
- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)
- [CVE-2025-11953](https://intel.threadlinqs.com/cve/CVE-2025-11953)
- [CVE-2025-40551](https://intel.threadlinqs.com/cve/CVE-2025-40551)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2026-12957](https://intel.threadlinqs.com/cve/CVE-2026-12957)
- [CVE-2026-12958](https://intel.threadlinqs.com/cve/CVE-2026-12958)
- [CVE-2026-20817](https://intel.threadlinqs.com/cve/CVE-2026-20817)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2026-50656](https://intel.threadlinqs.com/cve/CVE-2026-50656)
- [CVE-2026-90894](https://intel.threadlinqs.com/cve/CVE-2026-90894)

## Detection coverage

Threadlinqs maintains 36 detection rules mapped to T1559 (SPL 12, KQL 8, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.

36 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1559.001 Component Object Model](https://intel.threadlinqs.com/technique/T1559.001) — 10 tracked threats
- T1559.002 Dynamic Data Exchange — 0 tracked threats
- T1559.003 XPC Services — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1559
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
