Tool
schtasks
- First Reported
- May 10, 2026
- Latest Reported
- Jun 14, 2026
Reported Context (2)
- attack process, the threat actor actively uses legitimate Windows tools such as "curl", "tar", and "schtasks", while combining PowerShell execution policy bypass and CMD environment variable substring substitution. Genians Details NarwhalRAT Campaign Using Microsoft-Themed Phishing and Dead-Drop C2
- Internally, it was configured to reassemble and execute commands such as curl, mkdir, tar, del, ren, and schtasks. APT37-Linked Campaign Uses Phishing and Obfuscated Scripts to Deploy Python Backdoor
CVE (1)
Malware (3)
Threat Actors (1)
MITRE ATT&CK (31)
Vendors (2)
Products (6)
Tools (6)
Industries (2)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.