# T1055.012 Process Hollowing

> As of 2026-10-05, T1055.012 (Process Hollowing) appears in 51 tracked threats, first reported 2026-02-23 and most recently 2026-09-30, with linked actors including APT37, Earth Lamia, GrayBravo; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 51 (1 critical, 43 high, 7 medium)
- **First seen:** 2026-02-23
- **Last seen:** 2026-09-30
- **Threat actors:** 9
- **Detection rules:** 135 (counts only; Blue tier and above)

## Key facts

- **ID:** T1055.012
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1055
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1055/012/

## Activity timeline

T1055.012 first appeared in tracked threats on 2026-02-23 and was most recently reported on 2026-09-30. The busiest month was 2026-09 with 17 reports, and 51 of the 51 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1055.012 Process Hollowing is catalogued by MITRE ATT&CK under the Privilege Escalation and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of [T1055 Process Injection](https://intel.threadlinqs.com/technique/T1055). Threadlinqs maps 51 of 2623 tracked threats (1.9%) to it; by severity that is 1 critical, 43 high, 7 medium.

Threats that use T1055.012 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (34 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (33 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (32 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (32 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (31 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1055.012; the most frequent are [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [Earth Lamia](https://intel.threadlinqs.com/actor/Earth%20Lamia) (1), [GrayBravo](https://intel.threadlinqs.com/actor/GrayBravo) (1), [Konni APT](https://intel.threadlinqs.com/actor/Konni%20APT) (1), [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1055.012.

- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)

## Data sources

Telemetry that can reveal T1055.012, per MITRE ATT&CK.

- Process — OS API Execution, Process Access, Process Creation, Process Modification

## Threat actors using it

- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [Earth Lamia](https://intel.threadlinqs.com/actor/Earth%20Lamia) — 1
- [GrayBravo](https://intel.threadlinqs.com/actor/GrayBravo) — 1
- [Konni APT](https://intel.threadlinqs.com/actor/Konni%20APT) — 1
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 1
- [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) — 1
- [SNOWLIGHT](https://intel.threadlinqs.com/actor/SNOWLIGHT) — 1
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 1
- [UNC5174](https://intel.threadlinqs.com/actor/UNC5174) — 1

## Tracked threats

The 30 most recent of 51 tracked threats that use T1055.012.

- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — high — 2026-09-30
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…](https://intel.threadlinqs.com/threat/TL-2026-2631) — high — 2026-09-23
- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panel](https://intel.threadlinqs.com/threat/TL-2026-2621) — medium — 2026-09-22
- [Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…](https://intel.threadlinqs.com/threat/TL-2026-2615) — medium — 2026-09-22
- [ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…](https://intel.threadlinqs.com/threat/TL-2026-2589) — high — 2026-09-20
- [SmokeLoader Backdoor/Loader: Process Hollowing Injection into explorer.exe with Anti-VM/Anti-Debug Evasion…](https://intel.threadlinqs.com/threat/TL-2026-2482) — high — 2026-09-13
- [Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain](https://intel.threadlinqs.com/threat/TL-2026-2457) — high — 2026-09-12
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02
- [MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abuse](https://intel.threadlinqs.com/threat/TL-2026-2288) — high — 2026-09-02
- [Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment Methods](https://intel.threadlinqs.com/threat/TL-2026-2257) — medium — 2026-08-31
- [Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon](https://intel.threadlinqs.com/threat/TL-2026-2148) — high — 2026-08-26
- [Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…](https://intel.threadlinqs.com/threat/TL-2026-2120) — high — 2026-08-23
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…](https://intel.threadlinqs.com/threat/TL-2026-2096) — high — 2026-08-21
- [Post-DEF CON Phishing Campaign Abuses Google Apps Script Sidebar to Deliver AMOS Stealer and NetSupport RAT](https://intel.threadlinqs.com/threat/TL-2026-2449) — high — 2026-08-19
- [PhantomStealer Infostealer Distributed via Phishing Campaign with BYOVD Security Software Killer](https://intel.threadlinqs.com/threat/TL-2026-2055) — high — 2026-08-18
- [DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling](https://intel.threadlinqs.com/threat/TL-2026-2015) — high — 2026-08-14
- [VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defenses](https://intel.threadlinqs.com/threat/TL-2026-2014) — medium — 2026-08-14
- [HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)](https://intel.threadlinqs.com/threat/TL-2026-2013) — high — 2026-08-14
- [Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-2008) — high — 2026-08-13
- [Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…](https://intel.threadlinqs.com/threat/TL-2026-1918) — high — 2026-08-06
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)](https://intel.threadlinqs.com/threat/TL-2026-1651) — high — 2026-07-23

## Related CVEs

CVEs referenced by the tracked threats that use T1055.012, most frequent first.

- [CVE-2019-16098](https://intel.threadlinqs.com/cve/CVE-2019-16098)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-37042](https://intel.threadlinqs.com/cve/CVE-2022-37042)
- [CVE-2025-24054](https://intel.threadlinqs.com/cve/CVE-2025-24054)
- [CVE-2025-33053](https://intel.threadlinqs.com/cve/CVE-2025-33053)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)

## Detection coverage

Threadlinqs maintains 135 detection rules mapped to T1055.012 (SPL 48, KQL 49, Sigma 38). Rule content is available to Blue tier accounts and above; this page shows counts only.

135 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1055 Process Injection](https://intel.threadlinqs.com/technique/T1055) — 269 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1055.012
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
