T1620Reflective Code Loading
T1620 — Reflective Code Loading is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 10 detection use cases covering it and 9 threat-intel articles citing it.
Defense Evasion
10Use cases
9Articles
0Sub-techniques
1Tactic
Use cases covering this technique (10)
PowerShell PInvoke Process Injection API Chain Windows MMC Loaded Script Engine DLL [LLM] Linux root process executed from memfd (CVE-2026-53264 core-dump payload) [LLM] MIXEDKEY encrypted payload: .PCPKEY file dropped on disk [LLM] msaRAT msiexec executing update_ms.msi (fake Windows update custom action) [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) [LLM] Bun spawned from npm install context executing /tmp/p*.js implant [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from DownloadsArticles citing this technique (9)
crit Begun, the Patch Wars have art-151