T1497 - Virtualization/Sandbox Evasion is a mitre_attack tracked by ThreatCluster, appearing in 22 threat clusters built from 24 intelligence report mentions.
T1497 - Virtualization/Sandbox Evasion is a mitre_attack tracked across 22 threat clusters and 24 intelligence report mentions on ThreatCluster. First observed February 10, 2026; most recent activity July 22, 2026.
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering…
A Russian cyber campaign has been identified targeting Ukrainian organizations using new malware families, BadPaw and MeowMeow, delivered via phishing emails. The operation begins with emails containing links to ZIP…
On March 22, 2026, Huntress identified a campaign involving signed adware from Dragon Boss Solutions LLC that disabled antivirus protections on over 23,500 endpoints across 124 countries. The software, marketed as…
The KhangNghiem/fast-draft extension on Open VSX was found to contain multiple malicious releases that deploy a remote access trojan (RAT) and an infostealer. Versions 0.10.89, 0.10.105, 0.10.106, and 0.10.112 were…
OnyxC2 Stealer has emerged as a significant Malware-as-a-Service (MaaS) threat, targeting over 210 applications for credential theft and remote access. Sold for as low as $250 per month, it employs sophisticated evasion…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
The NWHStealer infostealer has adopted a new distribution method utilizing the Bun JavaScript runtime, enhancing its delivery infrastructure. This Rust-based malware targets Windows systems, leveraging Bun's performance…
A new cryptojacking campaign is targeting high-performance PC users through malicious downloads disguised as trusted utilities. Attackers leverage SEO poisoning and AI chatbot manipulation to direct users to fake…
A Russian-speaking cybercriminal group, dubbed BlackSanta, is targeting corporate HR teams by sending fake job applications that install malware capable of disabling endpoint detection and response (EDR) tools. This…
T1497 - Virtualization/Sandbox Evasion is a mitre_attack tracked by ThreatCluster, appearing in 22 threat clusters built from 24 intelligence report mentions.
The most recent intelligence report mentioning T1497 - Virtualization/Sandbox Evasion on ThreatCluster is dated July 22, 2026. Activity was first observed February 10, 2026, giving a tracked span from then to July 22, 2026.
Across ThreatCluster reporting, T1497 - Virtualization/Sandbox Evasion most frequently co-occurs with Apt28, Mango Sandstorm, MuddyWater, Mustang Panda, Seedworm, among 12 tracked related entities.
The most significant recent cluster is “Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage” (17 articles · Updated May 7, 2026). T1497 - Virtualization/Sandbox Evasion appears across 22 threat clusters in total, listed above with sources.
T1497 - Virtualization/Sandbox Evasion appears in 24 intelligence report mentions across 22 deduplicated threat clusters, aggregated from 17,000+ monitored sources.