Activity timeline
T1620 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 76 reports, and 242 of the 242 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1620 Reflective Code Loading is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 242 of 2623 tracked threats (9.2%) to it; by severity that is 45 critical, 181 high, 14 medium, 2 low.
Threats that use T1620 most often also use T1027 Obfuscated Files or Information (185 threats), T1082 System Information Discovery (166 threats), T1140 Deobfuscate/Decode Files or Information (163 threats), T1105 Ingress Tool Transfer (139 threats), T1005 Data from Local System (130 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
76 tracked threat actors appear in the threats that use T1620; the most frequent are APT38 (10), Andariel (8), Lazarus Group (8), Sapphire Sleet (8), Stardust Chollima (8).
Data sources
Telemetry that can reveal T1620, per MITRE ATT&CK.
- Module — Module Load
- Process — OS API Execution
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 242 tracked threats that use T1620.
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitationcritical
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…critical
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…critical
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…medium
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)high
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…critical
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2high
- SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…high
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…high
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chainhigh
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms…high
- Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channelhigh
Detection coverage
Threadlinqs maintains 320 detection rules mapped to T1620 (SPL 99, KQL 123, Sigma 98). Rule content is available to Blue tier accounts and above; this page shows counts only.