FORENSIA

ATT&CK · T1574

Hijack Execution Flow

Tactics: stealth, execution

About

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution. There are many ways an adversary may hijack the flow of execution, including by manipulating how the operating system locates programs to be executed. How the operating system locates libraries to be used by a program can also be intercepted. Locations where the operating system looks for programs/resources, such as file directories and in the case of Windows the Registry, could also be poisoned to include malicious payloads.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

0 known groups

No mapped actors.

Software

9 malware/tools implement this

DenisShimRatDtrackSaint BotCOATHANGERDarkGateRaspberry RobinNightdoorSPAWNCHIMERA

Corpus indicators tagged with this technique

63 indicators in the corpus carry T1574.

IndicatorTypeFamilySevSrc
cve-2025-2492cve852
cve-2020-22658cve852
cve-2020-22653cve852
59868381885b33f6c8809cd3d945da7d167439a3hashcryptojacking804
8c2cc585ad8a13a72a704c0fda0c9854hashcryptojacking804
ded08ae5df7f1b12e5fdb767dbbed0b1hashcryptojacking804
9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046sha256ransomware801
22d051c9cc458012b98e9bdca501759ehash802
5144bf4e32c5832c426ad3da55d45f026f66bc95hash802
8bfa2df2110c38dff2359a416ce14693hash802
a2421f7fd4be6b12382150033507af7aa8bf6241hash802
74414ed4b63aadec039b603c32762b80hashcryptojacking804
95856f2ce428c728d9781d3296558068hashcryptojacking804
c133c3dd9f7d6934598025047df41abfhashcryptojacking804
fc586cad94e5a10dd5be6a6ae6096bd02dfbfd094365bec87e788ed0798d6f67hashcryptojacking804
4741c2884d1ca3a40dadd3f3f61cb95a59b11f99a0f980dbadc663b85eb77a2asha256ransomware801
c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076bsha256ransomware801
5620f01284329f561b1839a36be55355hashcryptojacking804
18dedc0009f0927cba6425c84cce9883hashcryptojacking804
7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237sha256ransomware801
cc6fd90785a528883b0203138348df8bad69bb1asha1ransomware781
f0b182423107a04cf5f09b8559e656242a4fcc89sha1ransomware781
a12db7b72879ac0f46079efd8c67e8ca0621f73bsha1ransomware781
09b0bc41f8838949d5a1c442ee2e2ec9ff892fdcsha1ransomware781
https://joytion.com/contacturl752
https://www.dropbox.com/s/zhp1b06imehwylq/synaptics.rar?dl=1urlcryptojacking754
https://avipstudios.com/contacturl752
http://lakhov.com/contacturl752
http://202.144.192.29/audit.phpurlcryptojacking754
https://laislivon.com/contacturl752

Showing the top 30 by severity of 63.