# T1574 Hijack Execution Flow

> As of 2026-10-05, T1574 (Hijack Execution Flow) appears in 214 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including Mustang Panda, TeamPCP, Nightmare Eclipse; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 214 (69 critical, 131 high, 14 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-03
- **Threat actors:** 69
- **Detection rules:** 154 (counts only; Blue tier and above)

## Key facts

- **ID:** T1574
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1574/

## Activity timeline

T1574 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 54 reports, and 213 of the 214 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1574 Hijack Execution Flow is catalogued by MITRE ATT&CK under the Execution and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 214 of 2623 tracked threats (8.2%) to it; by severity that is 69 critical, 131 high, 14 medium.

Threats that use T1574 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (152 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (138 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (137 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (136 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (133 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

69 tracked threat actors appear in the threats that use T1574; the most frequent are [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) (8), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (7), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (6), [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) (5), [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (4).

## Mitigations

MITRE ATT&CK lists 10 mitigations for T1574.

- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1024 Restrict Registry Permissions](https://attack.mitre.org/mitigations/M1024/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1044 Restrict Library Loading](https://attack.mitre.org/mitigations/M1044/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)
- [M1052 User Account Control](https://attack.mitre.org/mitigations/M1052/)

## Data sources

Telemetry that can reveal T1574, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Module — Module Load
- Process — Process Creation
- Service — Service Metadata
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 8
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 7
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 6
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 5
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 4
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 4
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 3
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 3
- [Calypso](https://intel.threadlinqs.com/actor/Calypso) — 3
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 3
- [Snake](https://intel.threadlinqs.com/actor/Snake) — 3

## Tracked threats

The 30 most recent of 214 tracked threats that use T1574.

- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — high — 2026-10-03
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2](https://intel.threadlinqs.com/threat/TL-2026-2368) — high — 2026-09-07
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…](https://intel.threadlinqs.com/threat/TL-2026-2362) — high — 2026-09-06
- [FalconFlank: Unpatched Local Privilege Escalation PoC in CrowdStrike Falcon Sensor via Office Macro…](https://intel.threadlinqs.com/threat/TL-2026-2330) — high — 2026-09-04
- [Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…](https://intel.threadlinqs.com/threat/TL-2026-2304) — high — 2026-09-03
- [Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK](https://intel.threadlinqs.com/threat/TL-2026-2293) — high — 2026-09-02
- [ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2256) — high — 2026-08-31
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…](https://intel.threadlinqs.com/threat/TL-2026-2255) — medium — 2026-08-31
- [Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…](https://intel.threadlinqs.com/threat/TL-2026-2223) — high — 2026-08-29
- [TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India](https://intel.threadlinqs.com/threat/TL-2026-2202) — high — 2026-08-29
- [Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)](https://intel.threadlinqs.com/threat/TL-2026-2182) — high — 2026-08-28
- [SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2166) — medium — 2026-08-27
- [MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…](https://intel.threadlinqs.com/threat/TL-2026-2163) — high — 2026-08-27
- [Known Techniques, Unknown Speed: Aqua Security on How Frontier AI Collapses the Container Attack Chain](https://intel.threadlinqs.com/threat/TL-2026-2113) — high — 2026-08-22
- [SmartApeSG ClickFix Campaign Delivering Two-Stage RAT Infection via Fake CAPTCHA Social Engineering on…](https://intel.threadlinqs.com/threat/TL-2026-2101) — high — 2026-08-21
- [SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2090) — critical — 2026-08-20
- [AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2076) — critical — 2026-08-19
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bank](https://intel.threadlinqs.com/threat/TL-2026-1977) — high — 2026-08-10
- [Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft…](https://intel.threadlinqs.com/threat/TL-2026-1967) — critical — 2026-08-10
- [CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Host](https://intel.threadlinqs.com/threat/TL-2026-1919) — high — 2026-08-06
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…](https://intel.threadlinqs.com/threat/TL-2026-1917) — high — 2026-08-06
- [Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304…](https://intel.threadlinqs.com/threat/TL-2026-1905) — critical — 2026-08-06
- [Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via…](https://intel.threadlinqs.com/threat/TL-2026-1897) — critical — 2026-08-05
- [August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp…](https://intel.threadlinqs.com/threat/TL-2026-1891) — critical — 2026-08-05

## Related CVEs

CVEs referenced by the tracked threats that use T1574, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-20253](https://intel.threadlinqs.com/cve/CVE-2026-20253)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-3502](https://intel.threadlinqs.com/cve/CVE-2026-3502)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-45586](https://intel.threadlinqs.com/cve/CVE-2026-45586)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)

## Detection coverage

Threadlinqs maintains 154 detection rules mapped to T1574 (SPL 54, KQL 49, Sigma 49, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

154 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1574.001 DLL](https://intel.threadlinqs.com/technique/T1574.001) — 150 tracked threats
- T1574.002 DLL Side-Loading — 12 tracked threats
- T1574.004 Dylib Hijacking — 0 tracked threats
- T1574.005 Executable Installer File Permissions Weakness — 2 tracked threats
- [T1574.006 Dynamic Linker Hijacking](https://intel.threadlinqs.com/technique/T1574.006) — 15 tracked threats
- T1574.007 Path Interception by PATH Environment Variable — 2 tracked threats
- T1574.008 Path Interception by Search Order Hijacking — 0 tracked threats
- T1574.009 Path Interception by Unquoted Path — 2 tracked threats
- T1574.010 Services File Permissions Weakness — 1 tracked threat
- T1574.011 Services Registry Permissions Weakness — 4 tracked threats
- T1574.012 COR_PROFILER — 1 tracked threat
- T1574.013 KernelCallbackTable — 1 tracked threat
- T1574.014 AppDomainManager — 4 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1574
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
