Activity timeline
T1574 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 54 reports, and 213 of the 214 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1574 Hijack Execution Flow is catalogued by MITRE ATT&CK under the Execution and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 214 of 2623 tracked threats (8.2%) to it; by severity that is 69 critical, 131 high, 14 medium.
Threats that use T1574 most often also use T1059 Command and Scripting Interpreter (152 threats), T1082 System Information Discovery (138 threats), T1071 Application Layer Protocol (137 threats), T1036 Masquerading (136 threats), T1027 Obfuscated Files or Information (133 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
69 tracked threat actors appear in the threats that use T1574; the most frequent are Mustang Panda (8), TeamPCP (7), Nightmare Eclipse (6), Void Arachne (5), Chaotic Eclipse (4).
Mitigations
MITRE ATT&CK lists 10 mitigations for T1574.
Data sources
Telemetry that can reveal T1574, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Modification
- Module — Module Load
- Process — Process Creation
- Service — Service Metadata
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 214 tracked threats that use T1574.
- Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394high
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…high
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2high
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…high
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…high
- Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURKhigh
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…medium
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…high
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)high
- SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loadingmedium
- MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…high
- Known Techniques, Unknown Speed: Aqua Security on How Frontier AI Collapses the Container Attack Chainhigh
- SmartApeSG ClickFix Campaign Delivering Two-Stage RAT Infection via Fake CAPTCHA Social Engineering on…high
- SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governmentscritical
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructurecritical
- SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asiahigh
- TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bankhigh
- Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft…critical
- CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Hosthigh
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…high
- Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304…critical
- Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via…critical
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp…critical
Detection coverage
Threadlinqs maintains 154 detection rules mapped to T1574 (SPL 54, KQL 49, Sigma 49, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1574.001 DLL — 150 tracked threats
- T1574.002 DLL Side-Loading — 12 tracked threats
- T1574.004 Dylib Hijacking — 0 tracked threats
- T1574.005 Executable Installer File Permissions Weakness — 2 tracked threats
- T1574.006 Dynamic Linker Hijacking — 15 tracked threats
- T1574.007 Path Interception by PATH Environment Variable — 2 tracked threats
- T1574.008 Path Interception by Search Order Hijacking — 0 tracked threats
- T1574.009 Path Interception by Unquoted Path — 2 tracked threats
- T1574.010 Services File Permissions Weakness — 1 tracked threat
- T1574.011 Services Registry Permissions Weakness — 4 tracked threats
- T1574.012 COR_PROFILER — 1 tracked threat
- T1574.013 KernelCallbackTable — 1 tracked threat
- T1574.014 AppDomainManager — 4 tracked threats