# T1574.006 Dynamic Linker Hijacking

> As of 2026-10-05, T1574.006 (Dynamic Linker Hijacking) appears in 15 tracked threats, first reported 2021-11-25 and most recently 2026-10-01, with linked actors including Kapibala, Magecart, Velvet Ant; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 15 (5 critical, 8 high, 2 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-01
- **Threat actors:** 3
- **Detection rules:** 51 (counts only; Blue tier and above)

## Key facts

- **ID:** T1574.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1574
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1574/006/

## Activity timeline

T1574.006 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-01. The busiest month was 2026-09 with 5 reports, and 14 of the 15 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1574.006 Dynamic Linker Hijacking is catalogued by MITRE ATT&CK under the Execution and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix, as a sub-technique of [T1574 Hijack Execution Flow](https://intel.threadlinqs.com/technique/T1574). Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 5 critical, 8 high, 2 medium.

Threats that use T1574.006 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (11 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (10 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (9 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (7 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1574.006; the most frequent are [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) (1), [Magecart](https://intel.threadlinqs.com/actor/Magecart) (1), [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1574.006.

- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)

## Data sources

Telemetry that can reveal T1574.006, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Module — Module Load
- Process — Process Creation

## Threat actors using it

- [Kapibala](https://intel.threadlinqs.com/actor/Kapibala) — 1
- [Magecart](https://intel.threadlinqs.com/actor/Magecart) — 1
- [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) — 1

## Tracked threats

15 tracked threats use T1574.006.

- [Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks](https://intel.threadlinqs.com/threat/TL-2026-2830) — critical — 2026-10-01
- [Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files](https://intel.threadlinqs.com/threat/TL-2026-2812) — high — 2026-09-30
- [eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring](https://intel.threadlinqs.com/threat/TL-2026-2624) — medium — 2026-09-22
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…](https://intel.threadlinqs.com/threat/TL-2026-2619) — critical — 2026-09-22
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — medium — 2026-09-13
- [Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2](https://intel.threadlinqs.com/threat/TL-2026-2264) — high — 2026-08-30
- [CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-2151) — high — 2026-08-26
- [Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…](https://intel.threadlinqs.com/threat/TL-2026-0809) — high — 2026-06-15
- [AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc…](https://intel.threadlinqs.com/threat/TL-2026-0702) — high — 2026-06-07
- [CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via…](https://intel.threadlinqs.com/threat/TL-2026-0618) — high — 2026-05-28
- [Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…](https://intel.threadlinqs.com/threat/TL-2026-0456) — high — 2026-05-04
- [FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 Apple App Store Apps (SparkKitty-linked…](https://intel.threadlinqs.com/threat/TL-2026-0395) — critical — 2026-04-20
- [RESURGE Passive Rootkit — Ivanti Connect Secure CVE-2025-0282 Exploitation, CRC32 TLS Fingerprint C2, Covert…](https://intel.threadlinqs.com/threat/TL-2026-0163) — critical — 2026-03-02
- [NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date…](https://intel.threadlinqs.com/threat/TL-2026-0095) — high — 2021-11-25

## Related CVEs

CVEs referenced by the tracked threats that use T1574.006, most frequent first.

- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2024-23897](https://intel.threadlinqs.com/cve/CVE-2024-23897)
- [CVE-2025-0282](https://intel.threadlinqs.com/cve/CVE-2025-0282)
- [CVE-2026-104286](https://intel.threadlinqs.com/cve/CVE-2026-104286)
- [CVE-2026-17106](https://intel.threadlinqs.com/cve/CVE-2026-17106)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-56271](https://intel.threadlinqs.com/cve/CVE-2026-56271)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-7273](https://intel.threadlinqs.com/cve/CVE-2026-7273)

## Detection coverage

Threadlinqs maintains 51 detection rules mapped to T1574.006 (SPL 17, KQL 15, Sigma 19). Rule content is available to Blue tier accounts and above; this page shows counts only.

51 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1574 Hijack Execution Flow](https://intel.threadlinqs.com/technique/T1574) — 214 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1574.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
