Activity timeline
T1497.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 8 reports, and 31 of the 31 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1497.003 Time Based Checks is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix, as a sub-technique of T1497 Virtualization/Sandbox Evasion. Threadlinqs maps 31 of 2623 tracked threats (1.2%) to it; by severity that is 2 critical, 23 high, 6 medium.
Threats that use T1497.003 most often also use T1071.001 Web Protocols (26 threats), T1082 System Information Discovery (23 threats), T1204.002 Malicious File (19 threats), T1027 Obfuscated Files or Information (18 threats), T1059.001 PowerShell (17 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
15 tracked threat actors appear in the threats that use T1497.003; the most frequent are APT28 (2), Armored Likho (2), BlueDelta (2), Forest Blizzard (2), Midnight Blizzard (2).
Data sources
Telemetry that can reveal T1497.003, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 31 tracked threats that use T1497.003.
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…medium
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…medium
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to…high
- APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiyehigh
- BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoorhigh
- Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)high
- Kynx Stealer: MaaS Infostealer Targeting Crypto Wallets, Gaming Platforms, and AI Coding Toolscritical
- TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Reposhigh
- CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT…critical
- Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…medium
- CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaignhigh
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)high
- DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaignsmedium
- Armored Likho APT (Eagle Werewolf) Deploys AI-Generated Loaders to Drop BusySnake Python Stealer Against…high
- EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver…high
- JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…high
- Armored Likho APT Deploys BusySnake Python Stealer with PyArmor Obfuscation Against Government and Power…high
- DBatLoader (ModiLoader/NatsoLoader): Delphi-Compiled Windows Loader Using Layered Anti-Analysis…high
- Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via…high
- PawsRunner Steganography Loader Delivers Evolved .NET PureLogs Infostealerhigh
- Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator…high
- ClickFix macOS Trio: Loader/Script/Helper Campaigns Deliver SHub Stealer, AMOS, and Macsync Stealer with…high
- MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering…high
- CloudZ RAT with Pheno Plugin Hijacks Microsoft Phone Link to Steal SMS and OTPs (Cisco Talos, 2026-05)high
- Vshell C2 Framework — Chinese-Language Cobalt Strike Alternative in APT Campaigns (UNC5174/SNOWLIGHT…high
Detection coverage
Threadlinqs maintains 55 detection rules mapped to T1497.003 (SPL 18, KQL 19, Sigma 18). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1497 Virtualization/Sandbox Evasion — 282 tracked threats at the technique level.