Threadlinqs IntelligenceStart free

ATT&CK techniqueExecutionStealth (formerly Defense Evasion)

T1574 Hijack Execution Flow

ExecutionStealth (formerly Defense Evasion)Enterprise

As of 2026-10-05, T1574 (Hijack Execution Flow) appears in 214 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including Mustang Panda, TeamPCP, Nightmare Eclipse; it most often appears alongside T1059 (Command and Scripting Interpreter).

Tracked threats
21469 critical, 131 high, 14 medium
First seen
2021-11-25
Last seen
2026-10-03
Threat actors
69In the threats using it
Detection rules
154Blue tier and above

Data as of:

Activity timeline

T1574 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 54 reports, and 213 of the 214 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1574 Hijack Execution Flow is catalogued by MITRE ATT&CK under the Execution and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 214 of 2623 tracked threats (8.2%) to it; by severity that is 69 critical, 131 high, 14 medium.

Threats that use T1574 most often also use T1059 Command and Scripting Interpreter (152 threats), T1082 System Information Discovery (138 threats), T1071 Application Layer Protocol (137 threats), T1036 Masquerading (136 threats), T1027 Obfuscated Files or Information (133 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

69 tracked threat actors appear in the threats that use T1574; the most frequent are Mustang Panda (8), TeamPCP (7), Nightmare Eclipse (6), Void Arachne (5), Chaotic Eclipse (4).

Mitigations

MITRE ATT&CK lists 10 mitigations for T1574.

Data sources

Telemetry that can reveal T1574, per MITRE ATT&CK.

  • Command — Command Execution
  • File — File Creation, File Modification
  • Module — Module Load
  • Process — Process Creation
  • Service — Service Metadata
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 214 tracked threats that use T1574.

Detection coverage

Threadlinqs maintains 154 detection rules mapped to T1574 (SPL 54, KQL 49, Sigma 49, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

154 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1574.001 DLL — 150 tracked threats
  • T1574.002 DLL Side-Loading — 12 tracked threats
  • T1574.004 Dylib Hijacking — 0 tracked threats
  • T1574.005 Executable Installer File Permissions Weakness — 2 tracked threats
  • T1574.006 Dynamic Linker Hijacking — 15 tracked threats
  • T1574.007 Path Interception by PATH Environment Variable — 2 tracked threats
  • T1574.008 Path Interception by Search Order Hijacking — 0 tracked threats
  • T1574.009 Path Interception by Unquoted Path — 2 tracked threats
  • T1574.010 Services File Permissions Weakness — 1 tracked threat
  • T1574.011 Services Registry Permissions Weakness — 4 tracked threats
  • T1574.012 COR_PROFILER — 1 tracked threat
  • T1574.013 KernelCallbackTable — 1 tracked threat
  • T1574.014 AppDomainManager — 4 tracked threats