Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1497/T1497.001
MITRE ATT&CK Sub-Technique

T1497.001: System Checks

ShareXLinkedInRedditHN

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from [Virtualization/Sandbox Evasion](https://attack.mitre.org/techniques/T1497) during automated discovery to shape follow-on behaviors.(Citation: Deloitte Environment Awareness) Specific checks will vary based on the target and/or adversary, but may involve behaviors such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047), [PowerShell](https://attack.mitre.org/techniques/T1059/001), [System Information Discovery](https://attack.mitre.org/techniques/T1082), and [Query Registry](https://attack.mitre.org/techniques/T1012) to obtain system information and search for VME artifacts. Adversaries may search for VME artifacts in memory, processes, file system, hardware, and/or the Registry. Adversaries may use scripting to automate these checks into one script and then have the program exit if it determines the system to be a virtual environment. Checks could include generic system properties such as host/domain name and samples of network traffic. Adversaries may also check the network adapters addresses, CPU core count, and available memory/drive size. Once executed, malware may also use [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) to check if it was saved in a folder or file with unexpected or even analysis-related naming artifacts such as `malware`, `sample`, or `hash`. Other common checks may enumerate services running that are unique to these applications, installed programs on the system, manufacturer/product fields for strings relating to virtual machine applications, and VME-specific hardware/processor instructions.(Citation: McAfee Virtual Jan 2017) In applications like VMWare, adversaries can also use a special I/O port to send commands and receive output. Hardware checks, such as the presence of the fan, temperature, and audio devices, could also be used to gather evidence that can be indicative a virtual environment. Adversaries may also query for specific readings from these devices.(Citation: Unit 42 OilRig Sept 2018)

Tactics
StealthDiscovery
Platforms
Linux, macOS, Windows

▪Parent technique

T1497: Virtualization/Sandbox Evasion

▪Used by groups (7)

G0012DarkhotelG0047Gamaredon GroupG0049OilRigG0090WIRTEG0094KimsukyG0120EvilnumG1017Volt Typhoon

▪Software using this technique (60)

S0013PlugXmalwareS0024DyremalwareS0094Trojan.KaraganymalwareS0182FinFishermalwareS0192PupytoolS0226Smoke LoadermalwareS0237GravityRATmalwareS0240ROKRATmalwareS0242SynAckmalwareS0248ytymalwareS0260InvisiMolemalwareS0264OopsIEmalwareS0270RogueRobinmalwareS0332RemcostoolS0333UBoatRATmalwareS0337BadPatchmalwareS0352OSX_OCEANLOTUS.DmalwareS0354DenismalwareS0373AstarothmalwareS0396EvilBunnymalwareS0428PoetRATmalwareS0438AttormalwareS0439OkrummalwareS0527CSPY DownloadertoolS0531GrandoreiromalwareS0532LucifermalwareS0559SUNBURSTmalwareS0561GuLoadermalwareS0576MegaCortexmalwareS0588GoldMaxmalwareS0612WastedLockermalwareS0626P8RATmalwareS0627SodaMastermalwareS0637NativeZonemalwareS0644ObliqueRATmalwareS0650QakBotmalwareS0657BLUELIGHTmalwareS0679FerociousmalwareS0689WhisperGatemalwareS1018Saint BotmalwareS1019SharkmalwareS1039BumblebeemalwareS1048macOS.OSAMinermalwareS1064SVCReadymalwareS1066DarkTortillamalwareS1070Black BastamalwareS1086Snip3malwareS1087AsyncRATtoolS1111DarkGatemalwareS1122MispadumalwareS1130Raspberry RobinmalwareS1145PikabotmalwareS1147NightdoormalwareS1159DUSTTRAPmalwareS1160LatrodectusmalwareS1179ExbytemalwareS1180BlackByte RansomwaremalwareS1207XLoadermalwareS1213Lumma StealermalwareS9018HeartCryptmalware

▪Reference

T1497.001on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.