T1053.003 Cron in real malware

ATT&CK technique T1053.003 Cron appears in 1 publicly analyzed sample on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior).

Tactics: execution, persistence, privilege-escalation

Prevalence in the corpus

Example samples

Canonical technique definition: MITRE ATT&CK T1053.003 (ATT&CK v19.1, CC BY 4.0).

Frequently asked about T1053.003

How common is ATT&CK T1053.003 (Cron) in real malware?
ATT&CK technique T1053.003 Cron appears in 1 publicly analyzed sample on MalwareAnalyzer by Cyble, 0.0% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior).
What share of analyzed samples use T1053.003?
0.0% of the publicly analyzed corpus (1 of 113927 samples) exhibits T1053.003. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.

All ATT&CK techniques in the corpus · Latest analyzed threats