Activity timeline
T1497 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 97 reports, and 282 of the 282 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1497 Virtualization/Sandbox Evasion is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix. Threadlinqs maps 282 of 2623 tracked threats (10.8%) to it; by severity that is 36 critical, 222 high, 23 medium.
Threats that use T1497 most often also use T1027 Obfuscated Files or Information (251 threats), T1082 System Information Discovery (201 threats), T1071 Application Layer Protocol (175 threats), T1140 Deobfuscate/Decode Files or Information (168 threats), T1005 Data from Local System (165 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
93 tracked threat actors appear in the threats that use T1497; the most frequent are WageMole (9), APT28 (7), Contagious Interview (7), BlueDelta (6), Forest Blizzard (6).
Data sources
Telemetry that can reveal T1497, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 282 tracked threats that use T1497.
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoringmedium
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…high
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…high
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2high
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…high
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…high
- Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpithigh
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonationhigh
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Techniquemedium
- BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loadinghigh
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Servicehigh
- Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructurehigh
- REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…high
- FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…high
- BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…high
- US-First RMM Phishing Campaign Spans 46 Countries via Disposable Vercel/Netlify Infrastructure and…high
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…high
- Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accountshigh
- JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode Payloadshigh
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…medium
- Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed…medium
Detection coverage
Threadlinqs maintains 127 detection rules mapped to T1497 (SPL 34, KQL 43, Sigma 50). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1497.001 System Checks — 131 tracked threats
- T1497.002 User Activity Based Checks — 4 tracked threats
- T1497.003 Time Based Checks — 31 tracked threats