T1059.004Unix Shell
T1059.004 — Unix Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 113 detection use cases covering it and 75 threat-intel articles citing it.
Execution
113Use cases
75Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (113)
[WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Linux Decode Base64 to Shell Linux Magic SysRq Key Abuse Linux Suspicious React or Next.js Child Process Linux Unix Shell Enable All SysRq Functions MacOS LOLbin Suspicious Linux Discovery Commands [LLM] splunkd spawning shell interpreters (CVE-2026-20253 post-exploit RCE) [LLM] AUR helper or makepkg spawning npm/node to install atomic-lockfile or js-digest [LLM] Atomic Arch: makepkg child spawning npm install atomic-lockfile or bun install js-digest [LLM] Atomic Arch: deps ELF execution by SHA256/MD5 or src/hooks/deps path [LLM] Atomic Arch — pacman/makepkg post-install spawning npm install of atomic-lockfile [LLM] Atomic Arch — ELF payload 'deps' written or executed under build/cache directories after AUR install [LLM] Shell/LOLBin spawned by LangGraph Python or Node runtime [LLM] Ivanti Sentry CVE-2026-10520 handleMessage exploit attempt (commandexec XML) [LLM] Shell or recon binary spawned by Tomcat/Java on Ivanti Sentry (CVE-2026-10520 post-exploitation) [LLM] Self-hosted AI agent process spawns shell/curl/wget then executes the fetched payload [LLM] Webserver / PHP interpreter spawns shell or LOLBin — post-upload RCE indicator [LLM] MIPS shell-script dropper on Linux edge device — JDY architecture-aware payload fetch [LLM] Fortinet FortiSandbox WEB UI command injection HTTP pattern (CVE-2026-25089) [LLM] Pheditor CVE-2026-48030 — web server spawning shell interpreter from terminal handler RCE [LLM] Pheditor CVE-2026-48030 — shell metacharacters in 'dir' POST parameter to pheditor.php [LLM] Pheditor CVE-2026-48030 — webshell drop: PHP / web account writing .php to webroot [LLM] BEAM / Erlang VM spawns shell or interpreter child (post-RCE — CVE-2026-8467) [LLM] LiteLLM proxy (uvicorn/python) spawning shell or LOLBin — CVE-2026-42271 post-exploit [LLM] Web-server process (php-fpm / apache / nginx / w3wp) spawning shell or network tooling [LLM] Qilin Linux ransomware ELF payload (CVE-2026-50751 campaign) — known MD5 file event [LLM] Rclone exfiltration from Check Point VPN gateway or post-bypass internal host [LLM] DbGate node process spawning shell child (post-exploit RCE) [LLM] DbGate CVE-2026-47668 — Node.js runner spawning shell/LOLBin children for egress [LLM] Stata binary spawning OS shell (CVE-2026-47708 stata-mcp log_file_name injection) [LLM] Enterprise Gateway python container spawns shell or reads K8s service-account token (CVE-2026-44181 RCE) [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) [LLM] Suspicious child process spawned by PraisonAI uvicorn/python A2A server (eval() RCE evidence) [LLM] PraisonAI Python subprocess spawns OS shell with discovery / credential-reading commands [LLM] PraisonAI python process spawning shell, curl, or wget (post-exploitation tool-use abuse) [LLM] Node.js process spawning OS shell with enumeration commands — vm2 sandbox escape (CVE-2026-47137) [LLM] Web service in container spawning interactive shell (Redis/nginx RCE) [LLM] Yamcs JVM spawns shell or network utility (CVE-2026-46621 post-exploitation) [LLM] Yamcs JVM spawning a POSIX shell — Nashorn Runtime.exec post-exploitation [LLM] Reverse-shell /dev/tcp file descriptor from Yamcs java process tree [LLM] Hazy Scorpius (CL0P) Oracle EBS exploitation via CVE-2025-61882 — concurrent processing spawns shell/wget [LLM] Node.js web process spawning shell (LiquidJS RCE post-exploit) [LLM] Yamcs JVM spawning OS shell/interpreter (Janino RCE via CVE-2026-44632) [LLM] Composer install of malicious helpers.php in laravel-lang vendor package [LLM] nezha-agent spawning credential-access shell commands on Linux (post-RCE) [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner [LLM] 9router CVE-2026-46339 — GET /api/mcp/{plugin}/sse triggers stored command spawn() [LLM] 9router Node.js process spawning shell binary (CVE-2026-46339 post-exploit) [LLM] Reverse shell from 9router-spawned shell — outbound TCP from node-child bash [LLM] Kopia process spawns ssh with -oProxyCommand= argument (CVE-2026-45695) [LLM] SSH process spawned by Kopia invokes a shell child (ProxyCommand execution) [LLM] GlassFish java process spawning command shell (CVE-2026-2587 RCE) [LLM] Apache Camel JVM spawning shell or command interpreter via camel-exec (CVE-2026-47323 post-exploit) [LLM] Algernon web server spawning shell child process (CVE-2026-45721 handler.lua RCE) [LLM] MLflow server process spawning Claude Code CLI or shell — CVE-2026-2611 RCE chain [LLM] Web-server process (w3wp/php/nginx) spawns shell or LOLBin (post-SSTI RCE chain) [LLM] utcp-cli command injection via UTCP_ARG substitution in python→bash -c CMD_N_OUTPUT script [LLM] DeepSeek-TUI sub-agent shell execution via AGENTS.md prompt injection (CVE-2026-45374) [LLM] DeepSeek-TUI spawning 'cargo test' — CVE-2026-45311 auto-approved run_tests pathway [LLM] Rust cargo-test binary in target/debug/deps spawning shell or network tool (CVE-2026-45311 exploitation) [LLM] Container escape via chroot/nsenter against mounted host filesystem [LLM] n8n Node.js parent spawning OS shell — post-exploit RCE indicator for CVE-2026-44791 [LLM] Post-exploit RCE: node.js (n8n) spawning shell or scripting interpreter [LLM] AdaptixC2 'systemd-resolved' or Sliver 'CWan' implant on Linux / SD-WAN host [LLM] Flowise node.exe Spawning OS Shell or Command-Line Utility - Post-Exploit RCE (CVE-2026-46442) [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) [LLM] Qinglong CVE-2026-4047 case-mismatch auth bypass via /aPi/system/command-run [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) [LLM] Installation of credential-leaking ClawHub skills (moltyverse-email, buy-anything, prompt-log, youtube-data) [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line [LLM] curl | bash or wget | sh executed by Claude/Cursor/OpenClaw agent process [LLM] NPM preinstall hook fetching Bun installer from bun.sh (Sha1-Hulud dropper) [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] TruffleHog spawned by node/npm as postinstall — Shai-Hulud credential sweep [LLM] s1ngularity nx: AI CLI assistant invoked with permission-bypass flags (Claude/Gemini/Q) [LLM] GitHub Actions self-hosted runner spawning curl/wget POST to non-allowlisted egress [LLM] wdavdaemon or MDE Linux endpoints observed on CI/CD build runners [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags [LLM] Malicious tj-actions base64 payload prefix observed in process command line [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems`Articles citing this technique (75)
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-14
crit [GHSA / CRITICAL] CVE-2026-44789: n8n: HTTP Request Node Pagination Prototype Pollution to RCE art-301
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-349
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-433