# T1620 Reflective Code Loading

> As of 2026-10-05, T1620 (Reflective Code Loading) appears in 242 tracked threats, first reported 2026-01-14 and most recently 2026-10-02, with linked actors including APT38, Andariel, Lazarus Group; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 242 (45 critical, 181 high, 14 medium, 2 low)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-02
- **Threat actors:** 76
- **Detection rules:** 320 (counts only; Blue tier and above)

## Key facts

- **ID:** T1620
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1620/

## Activity timeline

T1620 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 76 reports, and 242 of the 242 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1620 Reflective Code Loading is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 242 of 2623 tracked threats (9.2%) to it; by severity that is 45 critical, 181 high, 14 medium, 2 low.

Threats that use T1620 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (185 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (166 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (163 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (139 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (130 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

76 tracked threat actors appear in the threats that use T1620; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (10), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (8), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (8), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (8), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (8).

## Data sources

Telemetry that can reveal T1620, per MITRE ATT&CK.

- Module — Module Load
- Process — OS API Execution
- Script — Script Execution

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 10
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 8
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 8
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 8
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 8
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 6
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 4
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 3
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 3
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 3
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 3
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 3

## Tracked threats

The 30 most recent of 242 tracked threats that use T1620.

- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — high — 2026-09-29
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2688) — critical — 2026-09-27
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-2680) — critical — 2026-09-25
- [Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)](https://intel.threadlinqs.com/threat/TL-2026-2617) — critical — 2026-09-22
- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…](https://intel.threadlinqs.com/threat/TL-2026-2606) — critical — 2026-09-21
- [PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…](https://intel.threadlinqs.com/threat/TL-2026-2593) — medium — 2026-09-20
- [ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…](https://intel.threadlinqs.com/threat/TL-2026-2589) — high — 2026-09-20
- [LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)](https://intel.threadlinqs.com/threat/TL-2026-2576) — high — 2026-09-19
- [Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…](https://intel.threadlinqs.com/threat/TL-2026-2561) — critical — 2026-09-18
- [MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2](https://intel.threadlinqs.com/threat/TL-2026-2560) — high — 2026-09-18
- [SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2554) — high — 2026-09-17
- [PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…](https://intel.threadlinqs.com/threat/TL-2026-2527) — high — 2026-09-15
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain](https://intel.threadlinqs.com/threat/TL-2026-2457) — high — 2026-09-12
- [ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-2455) — high — 2026-09-12
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms…](https://intel.threadlinqs.com/threat/TL-2026-2343) — high — 2026-09-05
- [Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channel](https://intel.threadlinqs.com/threat/TL-2026-2311) — high — 2026-09-03

## Related CVEs

CVEs referenced by the tracked threats that use T1620, most frequent first.

- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-65660](https://intel.threadlinqs.com/cve/CVE-2026-65660)
- [CVE-2026-67279](https://intel.threadlinqs.com/cve/CVE-2026-67279)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-11317](https://intel.threadlinqs.com/cve/CVE-2017-11317)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)

## Detection coverage

Threadlinqs maintains 320 detection rules mapped to T1620 (SPL 99, KQL 123, Sigma 98). Rule content is available to Blue tier accounts and above; this page shows counts only.

320 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1620
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
