T1055.012 - Process Hollowing - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
29
occurrences
First Seen
November 6, 2025
Last Seen
July 22, 2026

T1055.012 - Process Hollowing is a mitre_attack tracked across 23 threat clusters and 29 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 22, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • TrickBot Ditches HTTP for DNS Tunneling in Latest Variant — Infosecurity-Magazine · July 22, 2026
  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • 012 — attack.mitre.org · July 1, 2026
  • The SOC Files: ScreenConnect masked as freeware. An inside look at a large — Securelist · July 1, 2026
  • Fishmongers Arsenal Upgraded Sprysocks Windows — www.welivesecurity.com · June 19, 2026
  • New malspam campaign uses Google DoubleClick to deliver DesckVB RAT — Scworld · June 4, 2026
  • New Remcos Campaign Distributed Through Fake Shipping Document — www.fortinet.com · May 29, 2026
  • Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years — Securelist · May 28, 2026

CVSS v3.1 Breakdown