Activity timeline
T1569.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 17 reports, and 57 of the 57 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1569.002 Service Execution is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1569 System Services. Threadlinqs maps 57 of 2623 tracked threats (2.2%) to it; by severity that is 15 critical, 38 high, 4 medium.
Threats that use T1569.002 most often also use T1082 System Information Discovery (35 threats), T1027 Obfuscated Files or Information (33 threats), T1071.001 Web Protocols (33 threats), T1036.005 Match Legitimate Resource Name or Location (32 threats), T1005 Data from Local System (31 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
45 tracked threat actors appear in the threats that use T1569.002; the most frequent are GhostEmperor (3), APT38 (2), Akira (2), Andariel (2), Cavern Manticore (2).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1569.002.
Data sources
Telemetry that can reveal T1569.002, per MITRE ATT&CK.
- Command — Command Execution
- Network Traffic — Network Traffic Flow
- Process — Process Creation
- Service — Service Creation
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 57 tracked threats that use T1569.002.
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- TITAN Ransomware Claims AI Platform Analyzes 700GB of Stolen Data Per Hourhigh
- Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…critical
- UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firmshigh
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitationcritical
- Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoorscritical
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…critical
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demandsmedium
- Abuse of AWS Systems Manager (SSM) Agent as a Remote Access Trojanmedium
- Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…high
- HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset…high
- Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo[.]org…high
- LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry…high
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and…high
- LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day…high
- CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Daymedium
- LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Container Runtime to Backdoor Windows Hostshigh
- GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driverhigh
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…high
- FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx…critical
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege…critical
- ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software…high
- The BYOVD Epidemic: Attackers Weaponize Trusted Windows Drivers to Kill Security Softwarehigh
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)critical
- StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption)high
- ClockLauncher PHP Backdoor: php-win.exe LOLBin Abuse for Invisible Execution, LocalSystem Persistence, and…high
- AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian…high
- DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD…high
- EtherRAT: Node.js Remote Access Trojan with Ethereum Blockchain C2 Resolution and Per-Execution…high
Detection coverage
Threadlinqs maintains 68 detection rules mapped to T1569.002 (SPL 26, KQL 23, Sigma 19). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1569 System Services — 66 tracked threats at the technique level.