Activity timeline
T1055 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 83 reports, and 268 of the 269 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1055 Process Injection is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 269 of 2623 tracked threats (10.3%) to it; by severity that is 67 critical, 181 high, 21 medium.
Threats that use T1055 most often also use T1027 Obfuscated Files or Information (203 threats), T1082 System Information Discovery (203 threats), T1005 Data from Local System (154 threats), T1041 Exfiltration Over C2 Channel (154 threats), T1071 Application Layer Protocol (152 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
84 tracked threat actors appear in the threats that use T1055; the most frequent are APT38 (10), Sapphire Sleet (9), Stardust Chollima (9), Void Arachne (8), Andariel (6).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1055.
Data sources
Telemetry that can reveal T1055, per MITRE ATT&CK.
- File — File Metadata, File Modification
- Module — Module Load
- Process — OS API Execution, Process Access, Process Metadata, Process Modification
Threat actors using it
Tracked threats
The 30 most recent of 269 tracked threats that use T1055.
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitationcritical
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)high
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…high
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…high
- BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2high
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypasshigh
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Techniquemedium
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypasshigh
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…high
- Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE…high
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…high
- Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…high
- Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion…high
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breachhigh
- Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)high
- July 2026 Domestic APT Attack Trends (South Korea): LNK-Based Spear Phishing Delivering XenoRAT and…high
Detection coverage
Threadlinqs maintains 242 detection rules mapped to T1055 (SPL 79, KQL 90, Sigma 73). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1055.001 Dynamic-link Library Injection — 25 tracked threats
- T1055.002 Portable Executable Injection — 6 tracked threats
- T1055.003 Thread Execution Hijacking — 3 tracked threats
- T1055.004 Asynchronous Procedure Call — 15 tracked threats
- T1055.005 Thread Local Storage — 0 tracked threats
- T1055.008 Ptrace System Calls — 1 tracked threat
- T1055.009 Proc Memory — 2 tracked threats
- T1055.011 Extra Window Memory Injection — 0 tracked threats
- T1055.012 Process Hollowing — 51 tracked threats
- T1055.013 Process Doppelgänging — 3 tracked threats
- T1055.014 VDSO Hijacking — 0 tracked threats
- T1055.015 ListPlanting — 0 tracked threats