# T1497.001 System Checks

> As of 2026-10-05, T1497.001 (System Checks) appears in 131 tracked threats, first reported 2021-11-25 and most recently 2026-10-02, with linked actors including TeamPCP, UAT-11795, APT38; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 131 (15 critical, 103 high, 13 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-02
- **Threat actors:** 49
- **Detection rules:** 206 (counts only; Blue tier and above)

## Key facts

- **ID:** T1497.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion), Discovery
- **Matrix:** Enterprise
- **Parent:** T1497
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1497/001/

## Activity timeline

T1497.001 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 47 reports, and 130 of the 131 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1497.001 System Checks is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix, as a sub-technique of [T1497 Virtualization/Sandbox Evasion](https://intel.threadlinqs.com/technique/T1497). Threadlinqs maps 131 of 2623 tracked threats (5%) to it; by severity that is 15 critical, 103 high, 13 medium.

Threats that use T1497.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (108 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (95 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (91 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (85 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (81 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

49 tracked threat actors appear in the threats that use T1497.001; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (3), [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) (3), [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (2), [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) (2).

## Data sources

Telemetry that can reveal T1497.001, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 2
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 2
- [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) — 2
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Silver Fox APT](https://intel.threadlinqs.com/actor/Silver%20Fox%20APT) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 2
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1

## Tracked threats

The 30 most recent of 131 tracked threats that use T1497.001.

- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — high — 2026-10-02
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…](https://intel.threadlinqs.com/threat/TL-2026-2723) — high — 2026-09-27
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systems](https://intel.threadlinqs.com/threat/TL-2026-2612) — medium — 2026-09-22
- [ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…](https://intel.threadlinqs.com/threat/TL-2026-2589) — high — 2026-09-20
- [KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…](https://intel.threadlinqs.com/threat/TL-2026-2544) — high — 2026-09-16
- [SmokeLoader Backdoor/Loader: Process Hollowing Injection into explorer.exe with Anti-VM/Anti-Debug Evasion…](https://intel.threadlinqs.com/threat/TL-2026-2482) — high — 2026-09-13
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain](https://intel.threadlinqs.com/threat/TL-2026-2457) — high — 2026-09-12
- [ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-2455) — high — 2026-09-12
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…](https://intel.threadlinqs.com/threat/TL-2026-2387) — critical — 2026-09-08
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain](https://intel.threadlinqs.com/threat/TL-2026-2305) — high — 2026-09-03
- [Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teams](https://intel.threadlinqs.com/threat/TL-2026-2302) — high — 2026-09-02
- [Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment Methods](https://intel.threadlinqs.com/threat/TL-2026-2257) — medium — 2026-08-31
- [Infostealer Malware Hijacks Claude Login Sessions to Bypass MFA and Drain Usage; Related FakeAgent…](https://intel.threadlinqs.com/threat/TL-2026-2249) — high — 2026-08-30
- [Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage](https://intel.threadlinqs.com/threat/TL-2026-2234) — medium — 2026-08-30
- [Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to…](https://intel.threadlinqs.com/threat/TL-2026-2217) — high — 2026-08-29
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — high — 2026-08-29
- [Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts](https://intel.threadlinqs.com/threat/TL-2026-2167) — high — 2026-08-27
- [D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…](https://intel.threadlinqs.com/threat/TL-2026-2147) — high — 2026-08-25
- [ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer](https://intel.threadlinqs.com/threat/TL-2026-2142) — high — 2026-08-25
- [Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar Infostealer](https://intel.threadlinqs.com/threat/TL-2026-2132) — high — 2026-08-24

## Related CVEs

CVEs referenced by the tracked threats that use T1497.001, most frequent first.

- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003)
- [CVE-2022-48503](https://intel.threadlinqs.com/cve/CVE-2022-48503)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2023-43000](https://intel.threadlinqs.com/cve/CVE-2023-43000)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-62593](https://intel.threadlinqs.com/cve/CVE-2025-62593)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)

## Detection coverage

Threadlinqs maintains 206 detection rules mapped to T1497.001 (SPL 49, KQL 76, Sigma 81). Rule content is available to Blue tier accounts and above; this page shows counts only.

206 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1497 Virtualization/Sandbox Evasion](https://intel.threadlinqs.com/technique/T1497) — 282 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1497.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
