Threadlinqs IntelligenceStart free

ATT&CK techniqueStealth (formerly Defense Evasion)Discovery

T1622 Debugger Evasion

Stealth (formerly Defense Evasion)DiscoveryEnterprise

As of 2026-10-05, T1622 (Debugger Evasion) appears in 79 tracked threats, first reported 2026-01-14 and most recently 2026-09-30, with linked actors including TA578 - G1038, KongTuke, LockBit; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
7910 critical, 63 high, 6 medium
First seen
2026-01-14
Last seen
2026-09-30
Threat actors
32In the threats using it
Detection rules
68Blue tier and above

Data as of:

Activity timeline

T1622 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 26 reports, and 79 of the 79 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1622 Debugger Evasion is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix. Threadlinqs maps 79 of 2623 tracked threats (3%) to it; by severity that is 10 critical, 63 high, 6 medium.

Threats that use T1622 most often also use T1027 Obfuscated Files or Information (68 threats), T1082 System Information Discovery (62 threats), T1140 Deobfuscate/Decode Files or Information (45 threats), T1041 Exfiltration Over C2 Channel (40 threats), T1005 Data from Local System (39 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1622; the most frequent are TA578 - G1038 (3), KongTuke (2), LockBit (2), APT36 (1), APT37 (1).

Data sources

Telemetry that can reveal T1622, per MITRE ATT&CK.

  • Application Log — Application Log Content
  • Command — Command Execution
  • Process — OS API Execution, Process Creation

Threat actors using it

Tracked threats

The 30 most recent of 79 tracked threats that use T1622.

Detection coverage

Threadlinqs maintains 68 detection rules mapped to T1622 (SPL 20, KQL 23, Sigma 25). Rule content is available to Blue tier accounts and above; this page shows counts only.

68 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans