# T1055.004 Asynchronous Procedure Call

> As of 2026-10-05, T1055.004 (Asynchronous Procedure Call) appears in 15 tracked threats, first reported 2026-03-08 and most recently 2026-09-22, with linked actors including UAT-11795, LenAI; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 15 (11 high, 4 medium)
- **First seen:** 2026-03-08
- **Last seen:** 2026-09-22
- **Threat actors:** 2
- **Detection rules:** 23 (counts only; Blue tier and above)

## Key facts

- **ID:** T1055.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1055
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1055/004/

## Activity timeline

T1055.004 first appeared in tracked threats on 2026-03-08 and was most recently reported on 2026-09-22. The busiest month was 2026-08 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1055.004 Asynchronous Procedure Call is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of [T1055 Process Injection](https://intel.threadlinqs.com/technique/T1055). Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 11 high, 4 medium.

Threats that use T1055.004 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (12 threats), [T1547.001 Registry Run Keys / Startup Folder](https://intel.threadlinqs.com/technique/T1547.001) (11 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (10 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (10 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1055.004; the most frequent are [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) (2), [LenAI](https://intel.threadlinqs.com/actor/LenAI) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1055.004.

- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)

## Data sources

Telemetry that can reveal T1055.004, per MITRE ATT&CK.

- Process — OS API Execution, Process Access, Process Modification

## Threat actors using it

- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 2
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1

## Tracked threats

15 tracked threats use T1055.004.

- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panel](https://intel.threadlinqs.com/threat/TL-2026-2621) — medium — 2026-09-22
- [Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…](https://intel.threadlinqs.com/threat/TL-2026-2615) — medium — 2026-09-22
- [BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2426) — high — 2026-09-10
- [Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage](https://intel.threadlinqs.com/threat/TL-2026-2234) — medium — 2026-08-30
- [FTP Server Banners Abused as Dead-Drop Resolvers to Deliver E4del and PINHOLE Windows RATs](https://intel.threadlinqs.com/threat/TL-2026-2119) — high — 2026-08-23
- [New E4del and PINHOLE RATs Abuse FTP Server Banners as Dead-Drop Resolvers](https://intel.threadlinqs.com/threat/TL-2026-2117) — high — 2026-08-22
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…](https://intel.threadlinqs.com/threat/TL-2026-2096) — high — 2026-08-21
- [Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-2008) — high — 2026-08-13
- [Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig](https://intel.threadlinqs.com/threat/TL-2026-1979) — high — 2026-08-10
- [Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1454) — high — 2026-07-17
- [UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and…](https://intel.threadlinqs.com/threat/TL-2026-1411) — high — 2026-07-16
- [StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption)](https://intel.threadlinqs.com/threat/TL-2026-0941) — high — 2026-06-25
- [Operation GriefLure — China-Nexus APT Spear-Phishing Targeting Viettel (Vietnam Military Telecom) and St.…](https://intel.threadlinqs.com/threat/TL-2026-0476) — high — 2026-05-07
- [VOID#GEIST Multi-RAT Campaign — Early Bird APC Injection Delivering XWorm, AsyncRAT, and Xeno RAT via Python…](https://intel.threadlinqs.com/threat/TL-2026-0196) — high — 2026-03-08

## Related CVEs

CVEs referenced by the tracked threats that use T1055.004, most frequent first.

- [CVE-2019-16098](https://intel.threadlinqs.com/cve/CVE-2019-16098)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-37042](https://intel.threadlinqs.com/cve/CVE-2022-37042)

## Detection coverage

Threadlinqs maintains 23 detection rules mapped to T1055.004 (SPL 9, KQL 10, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

23 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1055 Process Injection](https://intel.threadlinqs.com/technique/T1055) — 269 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1055.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
