Activity timeline
T1027.007 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1027.007 Dynamic API Resolution is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1027 Obfuscated Files or Information. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 1 critical, 11 high, 1 medium.
Threats that use T1027.007 most often also use T1071.001 Web Protocols (11 threats), T1082 System Information Discovery (10 threats), T1140 Deobfuscate/Decode Files or Information (10 threats), T1036.005 Match Legitimate Resource Name or Location (9 threats), T1204.002 Malicious File (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1027.007; the most frequent are APT-C-60 (1), Contagious Interview (1), GrayBravo (1), KongTuke (1), Payouts King (1).
Data sources
Telemetry that can reveal T1027.007, per MITRE ATT&CK.
- File — File Metadata
- Module — Module Load
- Process — OS API Execution
Threat actors using it
Tracked threats
13 tracked threats use T1027.007.
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2high
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demonhigh
- CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)high
- Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAThigh
- Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…medium
- SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr…high
- JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…high
- Backdoor.Mistic (MLTBackdoor) — In-Memory BOF-Capable Backdoor Deployed by Woodgnat/KongTuke IAB Alongside…high
- Payouts King Ransomware — BlackBasta-Affiliate RaaS Evades EDR via Direct System Calls, ntdll Export-Table…high
- Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed…critical
Detection coverage
Threadlinqs maintains 23 detection rules mapped to T1027.007 (SPL 5, KQL 12, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1027 Obfuscated Files or Information — 1177 tracked threats at the technique level.