Threadlinqs IntelligenceStart free

ATT&CK techniqueStealth (formerly Defense Evasion)Discovery

T1497 Virtualization/Sandbox Evasion

Stealth (formerly Defense Evasion)DiscoveryEnterprise

As of 2026-10-05, T1497 (Virtualization/Sandbox Evasion) appears in 282 tracked threats, first reported 2026-01-14 and most recently 2026-09-30, with linked actors including WageMole, APT28, Contagious Interview; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
28236 critical, 222 high, 23 medium
First seen
2026-01-14
Last seen
2026-09-30
Threat actors
93In the threats using it
Detection rules
127Blue tier and above

Data as of:

Activity timeline

T1497 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 97 reports, and 282 of the 282 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1497 Virtualization/Sandbox Evasion is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix. Threadlinqs maps 282 of 2623 tracked threats (10.8%) to it; by severity that is 36 critical, 222 high, 23 medium.

Threats that use T1497 most often also use T1027 Obfuscated Files or Information (251 threats), T1082 System Information Discovery (201 threats), T1071 Application Layer Protocol (175 threats), T1140 Deobfuscate/Decode Files or Information (168 threats), T1005 Data from Local System (165 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

93 tracked threat actors appear in the threats that use T1497; the most frequent are WageMole (9), APT28 (7), Contagious Interview (7), BlueDelta (6), Forest Blizzard (6).

Data sources

Telemetry that can reveal T1497, per MITRE ATT&CK.

  • Command — Command Execution
  • Process — OS API Execution, Process Creation

Threat actors using it

Tracked threats

The 30 most recent of 282 tracked threats that use T1497.

Detection coverage

Threadlinqs maintains 127 detection rules mapped to T1497 (SPL 34, KQL 43, Sigma 50). Rule content is available to Blue tier accounts and above; this page shows counts only.

127 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques