Activity timeline
T1609 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 7 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1609 Container Administration Command is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 9 critical, 6 high.
Threats that use T1609 most often also use T1613 Container and Resource Discovery (13 threats), T1528 Steal Application Access Token (12 threats), T1190 Exploit Public-Facing Application (11 threats), T1552 Unsecured Credentials (10 threats), T1059 Command and Scripting Interpreter (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1609; the most frequent are TeamPCP (3), APT38 (1), Andariel (1), JADEPUFFER (1), Jade Sleet (1).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1609.
Data sources
Telemetry that can reveal T1609, per MITRE ATT&CK.
- Command — Command Execution
- Process — Process Creation
Threat actors using it
Tracked threats
15 tracked threats use T1609.
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize…critical
- CVE-2026-59726 (RufRoot): Unauthenticated RCE in Ruflo MCP Bridge Poisons AI Agent Memorycritical
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- Cryptojacking Campaign Exploiting Gogs (CVE-2026-52806) and Argo Workflows (CVE-2026-42296/CVE-2026-42295)…high
- Lone Attacker Uses AI-Assisted Workflows to Breach Large AWS Cloud Environment in 72 Hours (Sygnia…high
- Threat Actors Mass-Probe Gitea Docker Deployments for CVE-2026-20896 Authentication Bypass Amid Exploitarium…critical
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos…critical
- Linux Kernel cgroups v1 release_agent Container Escape & Privilege Escalation (CVE-2022-0492) — Added to…critical
- durabletask PyPI Supply Chain Compromise (v1.4.1–1.4.3) — Microsoft-Published Azure Durable Functions SDK…critical
- P2Pinfect Kubernetes Compromise — Exposed Redis Enables Persistent GKE Botnet Enrollment with Six-Month…high
- GitHub Internal Breach — TeamPCP Exfiltrates 3,800+ Repos via Poisoned VS Code Extension Tied to Mini…critical
- Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actorscritical
- Supply Chain Attacks on Crypto Ecosystem via Developer Toolchain Compromisehigh
Detection coverage
Threadlinqs maintains 12 detection rules mapped to T1609 (SPL 3, KQL 4, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.