T1620Reflective Code Loading
T1620 — Reflective Code Loading is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 9 detection use cases covering it and 8 threat-intel articles citing it.
Defense Evasion
9Use cases
8Articles
0Sub-techniques
1Tactic
Use cases covering this technique (9)
PowerShell PInvoke Process Injection API Chain Windows MMC Loaded Script Engine DLL [LLM] Bun runtime fetched from oven-sh GitHub releases during npm install [LLM] msaRAT msiexec executing update_ms.msi (fake Windows update custom action) [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) [LLM] Bun spawned from npm install context executing /tmp/p*.js implant [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from DownloadsArticles citing this technique (8)
crit Begun, the Patch Wars have art-253