T1059.004Unix Shell
T1059.004 — Unix Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 146 detection use cases covering it and 98 threat-intel articles citing it.
Execution
146Use cases
98Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (146)
[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Linux Decode Base64 to Shell Linux Magic SysRq Key Abuse Linux Suspicious React or Next.js Child Process Linux Unix Shell Enable All SysRq Functions MacOS LOLbin Suspicious Linux Discovery Commands [LLM] Cisco FMC www account runs package_info.pl on staged /var/tmp/license.tmp (CVE-2026-20316/20079) [LLM] Fluentd config injection via Flow/Output CRD record_transformer (block-close + @type exec) [LLM] Fluentd aggregator pod spawns a shell (out_exec RCE execution) [LLM] Shell/curl spawned under Fluentd aggregator makes external network egress (post-RCE C2/exfil) [LLM] JFrog Artifactory service process spawning a shell or downloader (RCE exploitation) [LLM] Ruflo MCP bridge unauthenticated tools/call terminal_execute (RufRoot CVE-2026-59726) [LLM] Ruflo/Node MCP bridge spawning interactive shell inside container (RufRoot RCE) [LLM] Gitea git process spawning shell / network tool via planted hook (CVE-2026-60004 RCE) [LLM] JFrog Artifactory service process spawning a shell or network tool (RCE) [LLM] vBulletin web-server process (php-fpm/apache/nginx) spawning OS shell after CVE-2026-61511 [LLM] LuCI luci-app-commands / ddns command injection with shell metacharacters — root RCE [LLM] n8n/Node.js process spawning shell or recon utility (sandbox-escape RCE) [LLM] GitLab Puma/Ruby worker (running as git) spawns shell or network tool — Oj .ipynb RCE landing [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) [LLM] redis-server spawns a shell/interpreter (system() from Redis RCE chain) [LLM] SleeperGem loader: ruby install script spawns shell running deploy.sh [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) [LLM] Web server daemon (php-fpm/apache/nginx/w3wp) spawning a shell or network tool — wp2shell post-exploit code execution [LLM] Pheditor terminal RCE: web-server/PHP process spawns shell (CVE-2026-55579) [LLM] Reverse shell via cron/webshell payload dropped through Anyquery AFW (/dev/tcp) [LLM] DIRAC FileCatalog checkDataset SQL injection carrying Python eval gadget (CVE-2026-61667) [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) [LLM] YesWiki Bazar CalcField eval() RCE — dangerous PHP functions in form-save request [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) [LLM] YesWiki CalcField exploit attempts — PHP parse/fatal errors from CalcField.php in syslog [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) [LLM] Joro native plugin RCE: joro process spawns interactive /bin/bash shell (CVE-2026-53649) [LLM] Nuclio CronJob container args carry injected shell (CVE-2026-52831 header/body OS command injection) [LLM] EGroupware web runtime (php-fpm/apache) spawning a shell or network tool — CVE-2026-27823 RCE execution [LLM] DOGLEASH ELF payload download from UAT-7810 servers on Linux/embedded devices [LLM] Langroid Python agent spawning shell/downloader child (os.system RCE) [LLM] Craft/PHP/IIS web worker spawning a command shell (Formie SSTI RCE outcome) [LLM] 9router unauthenticated MCP / cli-tools route RCE via process spawn — CVE-2026-46339 [LLM] 9router (node) process spawning 'sudo -S sh' — CVE-2026-59800 command injection primitive [LLM] 9router chain: node fetches tailscale.com/install.sh then spawns sudo -S sh within seconds [LLM] Mautic Twig SSTI RCE: PHP/web process spawns OS shell (CVE-2026-9558) [LLM] cluw macOS stealer shell dropper fetching payload from ClawHavoc/AMOS C2 IP [LLM] OpenClaw paste-site (rentry.co/glot.io) curl-pipe-bash semantic-hijack dropper [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) [LLM] Composer install of malicious helpers.php in laravel-lang vendor package [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) [LLM] Qinglong CVE-2026-4047 case-mismatch auth bypass via /aPi/system/command-run [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) [LLM] Installation of credential-leaking ClawHub skills (moltyverse-email, buy-anything, prompt-log, youtube-data) [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags [LLM] Malicious tj-actions base64 payload prefix observed in process command line [LLM] Apache Spark CVE-2022-33891 doAs command injection — shell spawned by Spark JVM running 'id -Gn' with metacharacters [LLM] GitPython CVE-2022-24439 RCE — git 'ext::sh' transport command injection via crafted clone URL [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com [LLM] ImageMagick 'convert -resize' command injection via sh -c in Go web app [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) [LLM] Package-manager install hook spawning host-recon curl/wget exfil (pre.sh pattern) [LLM] Install of ypvpctpbamdhxtkzdu malicious package set (django-yauth + siblings) [LLM] Ruby/Rails app server spawning a Unix shell (post-deserialization RCE) [LLM] Git argument injection via --upload-pack option spawned by web-app runtime [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) [LLM] Bash reverse shell via /dev/tcp file-descriptor redirection [LLM] Server application runtime spawning shell with /dev/tcp redirection (RCE to reverse shell) [LLM] Reverse shell via ncat -e spawned by Node.js app (SonicJS GraphQL path-traversal RCE) [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) [LLM] npm/yarn install spawning anomalous shell or working-dir binary (.npmrc/.yarnrc config override RCE) [LLM] Magento php-fpm/web-server spawning shell or download utility (CVE-2022-24086 RCE) [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE [LLM] Celery worker (Python) spawning a shell — CVE-2021-23727 stored command injection [LLM] Root shell spawned by pkexec with empty parent command line (PwnKit post-exploitation) [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBin [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation [LLM] npm/node install lifecycle spawning interactive or reverse shell [LLM] ImageMagick convert spawning shell/LOLBin child (ImageTragick CVE-2016-3714 RCE) [LLM] systeminformation inetChecksite curl argument injection (CVE-2020-7752) [LLM] Arbitrary child process from systeminformation inetChecksite shell pipeline [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome [LLM] Apache Airflow Celery worker spawns non-airflow child (command-injection RCE, CVE-2020-11981) [LLM] World-writable executable run as a shell (-c) — minimist polluted shell privesc payload [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) [LLM] Webmin password_change.cgi unauthenticated command injection exploit attempt (CVE-2019-15107) [LLM] Webmin RCE: miniserv/password_change.cgi spawning reverse shell (CVE-2019-15107) [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE [LLM] runc /proc/self/exe re-exec abuse (CVE-2019-5736 exploit primitive) [LLM] Zip Slip RCE: archive-extraction process spawns command interpreter [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805) [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit) [LLM] ImageMagick binary spawning shell/recon process (ImageTragick CVE-2016-3714 delegate RCE)Articles citing this technique (98)
crit [GHSA / CRITICAL] CVE-2026-53649: Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE art-219
crit [GHSA / CRITICAL] CVE-2026-59800: 9router: Missing Authorization and OS Command Injection art-257
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-316
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-472
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-555
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-753
crit Breaking out of message brokers art-3322