# T1027.007 Dynamic API Resolution

> As of 2026-10-05, T1027.007 (Dynamic API Resolution) appears in 13 tracked threats, first reported 2026-02-24 and most recently 2026-09-28, with linked actors including APT-C-60, Contagious Interview, GrayBravo; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 13 (1 critical, 11 high, 1 medium)
- **First seen:** 2026-02-24
- **Last seen:** 2026-09-28
- **Threat actors:** 7
- **Detection rules:** 23 (counts only; Blue tier and above)

## Key facts

- **ID:** T1027.007
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1027
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1027/007/

## Activity timeline

T1027.007 first appeared in tracked threats on 2026-02-24 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1027.007 Dynamic API Resolution is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 1 critical, 11 high, 1 medium.

Threats that use T1027.007 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (11 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (10 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (10 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (9 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1027.007; the most frequent are [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) (1), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (1), [GrayBravo](https://intel.threadlinqs.com/actor/GrayBravo) (1), [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) (1), [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) (1).

## Data sources

Telemetry that can reveal T1027.007, per MITRE ATT&CK.

- File — File Metadata
- Module — Module Load
- Process — OS API Execution

## Threat actors using it

- [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [GrayBravo](https://intel.threadlinqs.com/actor/GrayBravo) — 1
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 1
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 1
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 1
- [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat) — 1

## Tracked threats

13 tracked threats use T1027.007.

- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…](https://intel.threadlinqs.com/threat/TL-2026-2589) — high — 2026-09-20
- [MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2](https://intel.threadlinqs.com/threat/TL-2026-2560) — high — 2026-09-18
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon](https://intel.threadlinqs.com/threat/TL-2026-2148) — high — 2026-08-26
- [CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-1707) — high — 2026-07-26
- [Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAT](https://intel.threadlinqs.com/threat/TL-2026-1552) — high — 2026-07-19
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr…](https://intel.threadlinqs.com/threat/TL-2026-1284) — high — 2026-07-13
- [JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…](https://intel.threadlinqs.com/threat/TL-2026-1142) — high — 2026-07-06
- [Backdoor.Mistic (MLTBackdoor) — In-Memory BOF-Capable Backdoor Deployed by Woodgnat/KongTuke IAB Alongside…](https://intel.threadlinqs.com/threat/TL-2026-0933) — high — 2026-06-24
- [Payouts King Ransomware — BlackBasta-Affiliate RaaS Evades EDR via Direct System Calls, ntdll Export-Table…](https://intel.threadlinqs.com/threat/TL-2026-0692) — high — 2026-06-06
- [Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed…](https://intel.threadlinqs.com/threat/TL-2026-0139) — critical — 2026-02-24

## Related CVEs

CVEs referenced by the tracked threats that use T1027.007, most frequent first.

- [CVE-2026-42980](https://intel.threadlinqs.com/cve/CVE-2026-42980)

## Detection coverage

Threadlinqs maintains 23 detection rules mapped to T1027.007 (SPL 5, KQL 12, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

23 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) — 1177 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1027.007
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
