Activity timeline
T1055.012 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 17 reports, and 51 of the 51 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1055.012 Process Hollowing is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of T1055 Process Injection. Threadlinqs maps 51 of 2623 tracked threats (1.9%) to it; by severity that is 1 critical, 43 high, 7 medium.
Threats that use T1055.012 most often also use T1071.001 Web Protocols (34 threats), T1140 Deobfuscate/Decode Files or Information (33 threats), T1027 Obfuscated Files or Information (32 threats), T1082 System Information Discovery (32 threats), T1204.002 Malicious File (31 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1055.012; the most frequent are APT37 (1), Earth Lamia (1), GrayBravo (1), Konni APT (1), Mustang Panda (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1055.012.
Data sources
Telemetry that can reveal T1055.012, per MITRE ATT&CK.
- Process — OS API Execution, Process Access, Process Creation, Process Modification
Threat actors using it
Tracked threats
The 30 most recent of 51 tracked threats that use T1055.012.
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panelmedium
- Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…medium
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- SmokeLoader Backdoor/Loader: Process Hollowing Injection into explorer.exe with Anti-VM/Anti-Debug Evasion…high
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chainhigh
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…high
- MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abusehigh
- Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment Methodsmedium
- Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demonhigh
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…high
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…high
- Post-DEF CON Phishing Campaign Abuses Google Apps Script Sidebar to Deliver AMOS Stealer and NetSupport RAThigh
- PhantomStealer Infostealer Distributed via Phishing Campaign with BYOVD Security Software Killerhigh
- DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smugglinghigh
- VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defensesmedium
- HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)high
- Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat Actorshigh
- Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…high
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)high
Detection coverage
Threadlinqs maintains 135 detection rules mapped to T1055.012 (SPL 48, KQL 49, Sigma 38). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1055 Process Injection — 269 tracked threats at the technique level.