# T1497 Virtualization/Sandbox Evasion

> As of 2026-10-05, T1497 (Virtualization/Sandbox Evasion) appears in 282 tracked threats, first reported 2026-01-14 and most recently 2026-09-30, with linked actors including WageMole, APT28, Contagious Interview; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 282 (36 critical, 222 high, 23 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-09-30
- **Threat actors:** 93
- **Detection rules:** 127 (counts only; Blue tier and above)

## Key facts

- **ID:** T1497
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion), Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1497/

## Activity timeline

T1497 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 97 reports, and 282 of the 282 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1497 Virtualization/Sandbox Evasion is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix. Threadlinqs maps 282 of 2623 tracked threats (10.8%) to it; by severity that is 36 critical, 222 high, 23 medium.

Threats that use T1497 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (251 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (201 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (175 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (168 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (165 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

93 tracked threat actors appear in the threats that use T1497; the most frequent are [WageMole](https://intel.threadlinqs.com/actor/WageMole) (9), [APT28](https://intel.threadlinqs.com/actor/APT28) (7), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (7), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (6), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (6).

## Data sources

Telemetry that can reveal T1497, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 9
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 7
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 7
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 6
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 6
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 5
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 4
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 4
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 4
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 4

## Tracked threats

The 30 most recent of 282 tracked threats that use T1497.

- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…](https://intel.threadlinqs.com/threat/TL-2026-2730) — high — 2026-09-28
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited](https://intel.threadlinqs.com/threat/TL-2026-2667) — high — 2026-09-26
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25
- [eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring](https://intel.threadlinqs.com/threat/TL-2026-2624) — medium — 2026-09-22
- [North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…](https://intel.threadlinqs.com/threat/TL-2026-2581) — high — 2026-09-19
- [North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…](https://intel.threadlinqs.com/threat/TL-2026-2577) — high — 2026-09-19
- [MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2](https://intel.threadlinqs.com/threat/TL-2026-2560) — high — 2026-09-18
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpit](https://intel.threadlinqs.com/threat/TL-2026-2490) — high — 2026-09-14
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2456) — high — 2026-09-12
- [LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique](https://intel.threadlinqs.com/threat/TL-2026-2441) — medium — 2026-09-11
- [BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2426) — high — 2026-09-10
- [QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-2397) — high — 2026-09-08
- [Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2372) — high — 2026-09-07
- [REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…](https://intel.threadlinqs.com/threat/TL-2026-2370) — high — 2026-09-07
- [FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…](https://intel.threadlinqs.com/threat/TL-2026-2330) — high — 2026-09-04
- [BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…](https://intel.threadlinqs.com/threat/TL-2026-2315) — high — 2026-09-03
- [US-First RMM Phishing Campaign Spans 46 Countries via Disposable Vercel/Netlify Infrastructure and…](https://intel.threadlinqs.com/threat/TL-2026-2308) — high — 2026-09-03
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02
- [Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts](https://intel.threadlinqs.com/threat/TL-2026-2296) — high — 2026-09-02
- [JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode Payloads](https://intel.threadlinqs.com/threat/TL-2026-2259) — high — 2026-08-31
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…](https://intel.threadlinqs.com/threat/TL-2026-2255) — medium — 2026-08-31
- [Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed…](https://intel.threadlinqs.com/threat/TL-2026-2253) — medium — 2026-08-31

## Related CVEs

CVEs referenced by the tracked threats that use T1497, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-11882](https://intel.threadlinqs.com/cve/CVE-2017-11882)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2017-8570](https://intel.threadlinqs.com/cve/CVE-2017-8570)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2019-16098](https://intel.threadlinqs.com/cve/CVE-2019-16098)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-30952](https://intel.threadlinqs.com/cve/CVE-2021-30952)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003)

## Detection coverage

Threadlinqs maintains 127 detection rules mapped to T1497 (SPL 34, KQL 43, Sigma 50). Rule content is available to Blue tier accounts and above; this page shows counts only.

127 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1497.001 System Checks](https://intel.threadlinqs.com/technique/T1497.001) — 131 tracked threats
- T1497.002 User Activity Based Checks — 4 tracked threats
- [T1497.003 Time Based Checks](https://intel.threadlinqs.com/technique/T1497.003) — 31 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1497
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
