Activity timeline
T1497.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 47 reports, and 130 of the 131 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1497.001 System Checks is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix, as a sub-technique of T1497 Virtualization/Sandbox Evasion. Threadlinqs maps 131 of 2623 tracked threats (5%) to it; by severity that is 15 critical, 103 high, 13 medium.
Threats that use T1497.001 most often also use T1071.001 Web Protocols (108 threats), T1082 System Information Discovery (95 threats), T1027 Obfuscated Files or Information (91 threats), T1204.002 Malicious File (85 threats), T1140 Deobfuscate/Decode Files or Information (81 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
49 tracked threat actors appear in the threats that use T1497.001; the most frequent are TeamPCP (3), UAT-11795 (3), APT38 (2), Contagious Interview (2), Contagious Interview - G1052 (2).
Data sources
Telemetry that can reveal T1497.001, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 131 tracked threats that use T1497.001.
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…high
- SmokeLoader Backdoor/Loader: Process Hollowing Injection into explorer.exe with Anti-VM/Anti-Debug Evasion…high
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chainhigh
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…critical
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chainhigh
- Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teamshigh
- Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment Methodsmedium
- Infostealer Malware Hijacks Claude Login Sessions to Bypass MFA and Drain Usage; Related FakeAgent…high
- Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usagemedium
- Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to…high
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malwarehigh
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accountshigh
- D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…high
- ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealerhigh
- Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar Infostealerhigh
Detection coverage
Threadlinqs maintains 206 detection rules mapped to T1497.001 (SPL 49, KQL 76, Sigma 81). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1497 Virtualization/Sandbox Evasion — 282 tracked threats at the technique level.