Activity timeline
T1622 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 26 reports, and 79 of the 79 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1622 Debugger Evasion is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix. Threadlinqs maps 79 of 2623 tracked threats (3%) to it; by severity that is 10 critical, 63 high, 6 medium.
Threats that use T1622 most often also use T1027 Obfuscated Files or Information (68 threats), T1082 System Information Discovery (62 threats), T1140 Deobfuscate/Decode Files or Information (45 threats), T1041 Exfiltration Over C2 Channel (40 threats), T1005 Data from Local System (39 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
32 tracked threat actors appear in the threats that use T1622; the most frequent are TA578 - G1038 (3), KongTuke (2), LockBit (2), APT36 (1), APT37 (1).
Data sources
Telemetry that can reveal T1622, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 79 tracked threats that use T1622.
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoringmedium
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)high
- Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpithigh
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypasshigh
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…high
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…high
- MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…high
- CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…high
- Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar Infostealerhigh
- Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…high
- VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defensesmedium
- PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian…high
- Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRighigh
- Suspected Russian Actor Uses AI Slopsquatting to Publish 1,000+ Malicious npm Packages (WEL1DROPPER /…high
- Kynx Stealer: MaaS Infostealer Targeting Crypto Wallets, Gaming Platforms, and AI Coding Toolscritical
- Nearly 800 Malicious npm Packages Deliver Cross-Platform WEL1DROPPER RAT and Infostealer ('Flooding Dropper'…high
- macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…high
- TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Reposhigh
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Servicehigh
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…high
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXihigh
Detection coverage
Threadlinqs maintains 68 detection rules mapped to T1622 (SPL 20, KQL 23, Sigma 25). Rule content is available to Blue tier accounts and above; this page shows counts only.