T1053 - Scheduled Task - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
17
occurrences
First Seen
November 3, 2025
Last Seen
February 2, 2026

T1053 - Scheduled Task is a mitre_attack tracked across 18 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity February 2, 2026.

Related Threat Clusters

  • Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations

    The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…

    6 articles · Updated November 7, 2025
  • FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation

    A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…

    100 articles · Updated November 15, 2025
  • APT41 Cyber-Espionage Tactics Explored in Ransomware Emulations

    The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…

    14 articles · Updated January 6, 2026
  • Sandworm Hackers Target Ukraine's Grain Sector with Data-Wiping Malware

    The Russian state-backed hacker group Sandworm has launched a campaign using data-wiping malware against Ukrainian organizations, particularly focusing on the grain sector. This attack aims to disrupt critical…

    9 articles · Updated November 8, 2025
  • Cyberattacks Target Ukraine and EU via Microsoft Office Vulnerability

    CERT-UA has reported a new wave of cyberattacks targeting Ukrainian government agencies and EU organizations, exploiting the Microsoft Office vulnerability CVE-2026-21509. Attackers are using malicious emails disguised…

    59 articles · Updated February 2, 2026
  • WebRAT Malware Distributed via GitHub Exploits

    WebRAT malware, a backdoor with info-stealing capabilities, is being distributed through GitHub repositories claiming to host proof-of-concept exploits for recently disclosed vulnerabilities. Initially targeting gamers…

    4 articles · Updated December 23, 2025
  • Five Plead Guilty in North Korean IT Worker Fraud Scheme

    Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…

    39 articles · Updated November 17, 2025
  • TamperedChef Malware Campaign Targets Key Industries with Fake Installers

    The TamperedChef malware campaign has been identified as targeting organizations in healthcare, construction, and manufacturing sectors by distributing malicious software disguised as legitimate applications. Attackers…

    3 articles · Updated November 21, 2025
  • Curly COMrades Exploit Hyper-V for Covert Cyberespionage

    The Russian APT group Curly COMrades is exploiting Microsoft's Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows 10 systems. This tactic allows them to evade endpoint security measures…

    1 article · Updated November 5, 2025
  • Lazarus Group Linked to $30M Upbit Hack in South Korea

    South Korean authorities suspect that North Korea's Lazarus Group was behind a hack of Upbit, resulting in losses of approximately $30.4 million. The breach involved unusual activity in Solana tokens and led Upbit to…

    100 articles · Updated November 28, 2025

Recent Intelligence Reports

  • Russia-linked APT28 attackers already abusing new Microsoft Office zero — Theregister · February 2, 2026
  • AsyncRAT Phishing Chain Abuses WebDAV and Cloudflare — Socprime · January 14, 2026
  • Hackers Use Fake PayPal Notices to Steal Credentials, Deploy RMMs — Infosecurity-Magazine · January 14, 2026
  • WebRAT malware spread via fake vulnerability exploits on GitHub — Bleepingcomputer · December 23, 2025
  • SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics — Trendmicro · December 12, 2025
  • Fake Leonardo DiCaprio torrent spreads Agent Tesla trojan — Securitybrief.Au · December 10, 2025
  • Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain — Bitdefender · December 10, 2025
  • Threat Actors Leverage Fake Update Lures to Deliver SocGholish Malware — Cybersecuritynews · November 27, 2025

CVSS v3.1 Breakdown