Threadlinqs IntelligenceStart free

ATT&CK techniquePrivilege EscalationStealth (formerly Defense Evasion)

T1055 Process Injection

Privilege EscalationStealth (formerly Defense Evasion)Enterprise

As of 2026-10-05, T1055 (Process Injection) appears in 269 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
26967 critical, 181 high, 21 medium
First seen
2021-11-25
Last seen
2026-10-03
Threat actors
84In the threats using it
Detection rules
242Blue tier and above

Data as of:

Activity timeline

T1055 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 83 reports, and 268 of the 269 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1055 Process Injection is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 269 of 2623 tracked threats (10.3%) to it; by severity that is 67 critical, 181 high, 21 medium.

Threats that use T1055 most often also use T1027 Obfuscated Files or Information (203 threats), T1082 System Information Discovery (203 threats), T1005 Data from Local System (154 threats), T1041 Exfiltration Over C2 Channel (154 threats), T1071 Application Layer Protocol (152 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

84 tracked threat actors appear in the threats that use T1055; the most frequent are APT38 (10), Sapphire Sleet (9), Stardust Chollima (9), Void Arachne (8), Andariel (6).

Mitigations

MITRE ATT&CK lists 2 mitigations for T1055.

Data sources

Telemetry that can reveal T1055, per MITRE ATT&CK.

  • File — File Metadata, File Modification
  • Module — Module Load
  • Process — OS API Execution, Process Access, Process Metadata, Process Modification

Threat actors using it

Tracked threats

The 30 most recent of 269 tracked threats that use T1055.

Detection coverage

Threadlinqs maintains 242 detection rules mapped to T1055 (SPL 79, KQL 90, Sigma 73). Rule content is available to Blue tier accounts and above; this page shows counts only.

242 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1055.001 Dynamic-link Library Injection — 25 tracked threats
  • T1055.002 Portable Executable Injection — 6 tracked threats
  • T1055.003 Thread Execution Hijacking — 3 tracked threats
  • T1055.004 Asynchronous Procedure Call — 15 tracked threats
  • T1055.005 Thread Local Storage — 0 tracked threats
  • T1055.008 Ptrace System Calls — 1 tracked threat
  • T1055.009 Proc Memory — 2 tracked threats
  • T1055.011 Extra Window Memory Injection — 0 tracked threats
  • T1055.012 Process Hollowing — 51 tracked threats
  • T1055.013 Process Doppelgänging — 3 tracked threats
  • T1055.014 VDSO Hijacking — 0 tracked threats
  • T1055.015 ListPlanting — 0 tracked threats