# T1622 Debugger Evasion

> As of 2026-10-05, T1622 (Debugger Evasion) appears in 79 tracked threats, first reported 2026-01-14 and most recently 2026-09-30, with linked actors including TA578 - G1038, KongTuke, LockBit; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 79 (10 critical, 63 high, 6 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-09-30
- **Threat actors:** 32
- **Detection rules:** 68 (counts only; Blue tier and above)

## Key facts

- **ID:** T1622
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion), Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1622/

## Activity timeline

T1622 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 26 reports, and 79 of the 79 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1622 Debugger Evasion is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) and Discovery tactics in the Enterprise matrix. Threadlinqs maps 79 of 2623 tracked threats (3%) to it; by severity that is 10 critical, 63 high, 6 medium.

Threats that use T1622 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (68 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (62 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (45 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (40 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (39 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1622; the most frequent are [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) (3), [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) (2), [LockBit](https://intel.threadlinqs.com/actor/LockBit) (2), [APT36](https://intel.threadlinqs.com/actor/APT36) (1), [APT37](https://intel.threadlinqs.com/actor/APT37) (1).

## Data sources

Telemetry that can reveal T1622, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 3
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 2
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 2
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 1
- [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) — 1

## Tracked threats

The 30 most recent of 79 tracked threats that use T1622.

- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…](https://intel.threadlinqs.com/threat/TL-2026-2723) — high — 2026-09-27
- [MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor module](https://intel.threadlinqs.com/threat/TL-2026-2641) — high — 2026-09-24
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2626) — medium — 2026-09-23
- [eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring](https://intel.threadlinqs.com/threat/TL-2026-2624) — medium — 2026-09-22
- [LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)](https://intel.threadlinqs.com/threat/TL-2026-2576) — high — 2026-09-19
- [Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpit](https://intel.threadlinqs.com/threat/TL-2026-2490) — high — 2026-09-14
- [Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass](https://intel.threadlinqs.com/threat/TL-2026-2481) — high — 2026-09-13
- [ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-2455) — high — 2026-09-12
- [REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…](https://intel.threadlinqs.com/threat/TL-2026-2370) — high — 2026-09-07
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02
- [MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…](https://intel.threadlinqs.com/threat/TL-2026-2163) — high — 2026-08-27
- [CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…](https://intel.threadlinqs.com/threat/TL-2026-2135) — high — 2026-08-24
- [Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar Infostealer](https://intel.threadlinqs.com/threat/TL-2026-2132) — high — 2026-08-24
- [Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2108) — high — 2026-08-22
- [VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defenses](https://intel.threadlinqs.com/threat/TL-2026-2014) — medium — 2026-08-14
- [PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian…](https://intel.threadlinqs.com/threat/TL-2026-2006) — high — 2026-08-13
- [Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig](https://intel.threadlinqs.com/threat/TL-2026-1979) — high — 2026-08-10
- [Suspected Russian Actor Uses AI Slopsquatting to Publish 1,000+ Malicious npm Packages (WEL1DROPPER /…](https://intel.threadlinqs.com/threat/TL-2026-1951) — high — 2026-08-09
- [Kynx Stealer: MaaS Infostealer Targeting Crypto Wallets, Gaming Platforms, and AI Coding Tools](https://intel.threadlinqs.com/threat/TL-2026-1943) — critical — 2026-08-08
- [Nearly 800 Malicious npm Packages Deliver Cross-Platform WEL1DROPPER RAT and Infostealer ('Flooding Dropper'…](https://intel.threadlinqs.com/threat/TL-2026-1935) — high — 2026-08-07
- [macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…](https://intel.threadlinqs.com/threat/TL-2026-1894) — high — 2026-08-05
- [TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Repos](https://intel.threadlinqs.com/threat/TL-2026-1859) — high — 2026-08-04
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…](https://intel.threadlinqs.com/threat/TL-2026-1809) — high — 2026-08-01
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXi](https://intel.threadlinqs.com/threat/TL-2026-1773) — high — 2026-07-30

## Related CVEs

CVEs referenced by the tracked threats that use T1622, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-29059](https://intel.threadlinqs.com/cve/CVE-2023-29059)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2024-21338](https://intel.threadlinqs.com/cve/CVE-2024-21338)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-23897](https://intel.threadlinqs.com/cve/CVE-2024-23897)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2024-7971](https://intel.threadlinqs.com/cve/CVE-2024-7971)

## Detection coverage

Threadlinqs maintains 68 detection rules mapped to T1622 (SPL 20, KQL 23, Sigma 25). Rule content is available to Blue tier accounts and above; this page shows counts only.

68 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1622
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
