# T1609 Container Administration Command

> As of 2026-10-05, T1609 (Container Administration Command) appears in 15 tracked threats, first reported 2026-03-19 and most recently 2026-09-27, with linked actors including TeamPCP, APT38, Andariel; it most often appears alongside T1613 (Container and Resource Discovery).

- **Tracked threats:** 15 (9 critical, 6 high)
- **First seen:** 2026-03-19
- **Last seen:** 2026-09-27
- **Threat actors:** 8
- **Detection rules:** 12 (counts only; Blue tier and above)

## Key facts

- **ID:** T1609
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1609/

## Activity timeline

T1609 first appeared in tracked threats on 2026-03-19 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 7 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1609 Container Administration Command is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 9 critical, 6 high.

Threats that use T1609 most often also use [T1613 Container and Resource Discovery](https://intel.threadlinqs.com/technique/T1613) (13 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (12 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (11 threats), [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) (10 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1609; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (3), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (1), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) (1), [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) (1).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1609.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1609, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 1
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [Slow Pisces](https://intel.threadlinqs.com/actor/Slow%20Pisces) — 1
- [TraderTraitor](https://intel.threadlinqs.com/actor/TraderTraitor) — 1

## Tracked threats

15 tracked threats use T1609.

- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize…](https://intel.threadlinqs.com/threat/TL-2026-2629) — critical — 2026-09-23
- [CVE-2026-59726 (RufRoot): Unauthenticated RCE in Ruflo MCP Bridge Poisons AI Agent Memory](https://intel.threadlinqs.com/threat/TL-2026-1762) — critical — 2026-07-29
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [Cryptojacking Campaign Exploiting Gogs (CVE-2026-52806) and Argo Workflows (CVE-2026-42296/CVE-2026-42295)…](https://intel.threadlinqs.com/threat/TL-2026-1230) — high — 2026-07-11
- [Lone Attacker Uses AI-Assisted Workflows to Breach Large AWS Cloud Environment in 72 Hours (Sygnia…](https://intel.threadlinqs.com/threat/TL-2026-1182) — high — 2026-07-10
- [Threat Actors Mass-Probe Gitea Docker Deployments for CVE-2026-20896 Authentication Bypass Amid Exploitarium…](https://intel.threadlinqs.com/threat/TL-2026-1136) — critical — 2026-07-06
- [JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos…](https://intel.threadlinqs.com/threat/TL-2026-1083) — critical — 2026-07-02
- [Linux Kernel cgroups v1 release_agent Container Escape & Privilege Escalation (CVE-2022-0492) — Added to…](https://intel.threadlinqs.com/threat/TL-2026-0662) — critical — 2026-06-02
- [durabletask PyPI Supply Chain Compromise (v1.4.1–1.4.3) — Microsoft-Published Azure Durable Functions SDK…](https://intel.threadlinqs.com/threat/TL-2026-0580) — critical — 2026-05-25
- [P2Pinfect Kubernetes Compromise — Exposed Redis Enables Persistent GKE Botnet Enrollment with Six-Month…](https://intel.threadlinqs.com/threat/TL-2026-0537) — high — 2026-05-21
- [GitHub Internal Breach — TeamPCP Exfiltrates 3,800+ Repos via Poisoned VS Code Extension Tied to Mini…](https://intel.threadlinqs.com/threat/TL-2026-0536) — critical — 2026-05-20
- [Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-0327) — critical — 2026-04-06
- [Supply Chain Attacks on Crypto Ecosystem via Developer Toolchain Compromise](https://intel.threadlinqs.com/threat/TL-2026-0248) — high — 2026-03-19

## Related CVEs

CVEs referenced by the tracked threats that use T1609, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-0543](https://intel.threadlinqs.com/cve/CVE-2022-0543)
- [CVE-2025-11953](https://intel.threadlinqs.com/cve/CVE-2025-11953)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-49844](https://intel.threadlinqs.com/cve/CVE-2025-49844)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-69263](https://intel.threadlinqs.com/cve/CVE-2025-69263)
- [CVE-2025-69264](https://intel.threadlinqs.com/cve/CVE-2025-69264)
- [CVE-2026-20896](https://intel.threadlinqs.com/cve/CVE-2026-20896)
- [CVE-2026-22874](https://intel.threadlinqs.com/cve/CVE-2026-22874)
- [CVE-2026-25038](https://intel.threadlinqs.com/cve/CVE-2026-25038)
- [CVE-2026-27771](https://intel.threadlinqs.com/cve/CVE-2026-27771)
- [CVE-2026-27775](https://intel.threadlinqs.com/cve/CVE-2026-27775)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-55255](https://intel.threadlinqs.com/cve/CVE-2026-55255)
- [CVE-2026-58053](https://intel.threadlinqs.com/cve/CVE-2026-58053)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)
- [CVE-2026-66014](https://intel.threadlinqs.com/cve/CVE-2026-66014)

## Detection coverage

Threadlinqs maintains 12 detection rules mapped to T1609 (SPL 3, KQL 4, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

12 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1609
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
