FORENSIA

ATT&CK · T1574

Hijack Execution Flow

Tactics: stealth, execution

About

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution. There are many ways an adversary may hijack the flow of execution, including by manipulating how the operating system locates programs to be executed. How the operating system locates libraries to be used by a program can also be intercepted. Locations where the operating system looks for programs/resources, such as file directories and in the case of Windows the Registry, could also be poisoned to include malicious payloads.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

0 known groups

No mapped actors.

Software

9 malware/tools implement this

DenisShimRatDtrackSaint BotCOATHANGERDarkGateRaspberry RobinNightdoorSPAWNCHIMERA

Corpus indicators tagged with this technique

63 indicators in the corpus carry T1574.

IndicatorTypeFamilySevSrc
cve-2025-2492cve852
cve-2020-22658cve852
cve-2020-22653cve852
95856f2ce428c728d9781d3296558068hashcryptojacking804
59868381885b33f6c8809cd3d945da7d167439a3hashcryptojacking804
74414ed4b63aadec039b603c32762b80hashcryptojacking804
8c2cc585ad8a13a72a704c0fda0c9854hashcryptojacking804
fc586cad94e5a10dd5be6a6ae6096bd02dfbfd094365bec87e788ed0798d6f67hashcryptojacking804
c133c3dd9f7d6934598025047df41abfhashcryptojacking804
8bfa2df2110c38dff2359a416ce14693hash802
ded08ae5df7f1b12e5fdb767dbbed0b1hashcryptojacking804
9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046sha256ransomware801
c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076bsha256ransomware801
18dedc0009f0927cba6425c84cce9883hashcryptojacking804
5620f01284329f561b1839a36be55355hashcryptojacking804
a2421f7fd4be6b12382150033507af7aa8bf6241hash802
4741c2884d1ca3a40dadd3f3f61cb95a59b11f99a0f980dbadc663b85eb77a2asha256ransomware801
22d051c9cc458012b98e9bdca501759ehash802
5144bf4e32c5832c426ad3da55d45f026f66bc95hash802
7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237sha256ransomware801
cc6fd90785a528883b0203138348df8bad69bb1asha1ransomware781
f0b182423107a04cf5f09b8559e656242a4fcc89sha1ransomware781
a12db7b72879ac0f46079efd8c67e8ca0621f73bsha1ransomware781
09b0bc41f8838949d5a1c442ee2e2ec9ff892fdcsha1ransomware781
http://lakhov.com/contacturl752
https://docs.google.com/uc?id=0bxsmxgfpizfsvzuyahfyvkqxefk&export=downloadurlcryptojacking754
https://joytion.com/contacturl752
https://www.dropbox.com/s/zhp1b06imehwylq/synaptics.rar?dl=1urlcryptojacking754
https://laislivon.com/contacturl752
http://202.144.192.29/audit.phpurlcryptojacking754

Showing the top 30 by severity of 63.