ATT&CK Technique · Stealth
T1620 Reflective Code LoadingMapped by 13 reports, 20 detection rules and 10 tracked actors on The Hunters Ledger. Technique page on attack.mitre.org.
← All techniques and the coverage heatmap
Reports
Each report maps this technique in its own ATT&CK table, at the confidence the report states. The link opens that table.
Detection rules
Rules whose ATT&CK coverage line names this technique, by detection page. The link opens the page's coverage table.
Detection rules
Sliver C2 Windows Post-Exploitation Staging, 193.233.202.17Reflective .NET Assembly Load From A Base64-Encoded PowerShell String (SIGMA, Hunting)
Detection rules
CloudSync: An Assembler's Intrusion ToolkitParalell Injector and SvchostPayload Type Names (YARA, Detection)
Detection rules
EvilSoul-Engine: A Brazilian Stealer-Builder Malware-as-a-Servicexaitax ChromElevator ABE-Bypass Tool: @breakingupslow Fork (YARA, Detection)
Detection rules
Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging HostNPCInfoList1.aspx: AES .NET Loader Webshell (Godzilla-Style) (YARA, Detection)
Detection rules
GHOST Cryptojacker Kit — Vova75Rus Supply Chain (77.110.96.200)High-Frequency memfd_create Syscall from Non-JVM Process on Linux Server (SIGMA, Hunting)
Detection rules
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaignpe_03 HijackLoader Stage-3 Loader (API Hash Table) (YARA, Detection)
Detection rules
AdaptixC2 Open Directory Exposure (45.130.148.125)AdaptixC2 PowerShell Loader: AMSI Bypass and SI Injector Invocation (YARA, Hunting); AdaptixC2 PowerShell Loader: AMSI Bypass and SI Injector Invocation (SIGMA, Hunting); Suspicious .NET Assembly Image Load with Operator si_build Build Fingerprint (SIGMA, Hunting)
Detection rules
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13)mymain Build In-Memory Crypter Keys (YARA, Hunting); myfile Build In-Memory Crypter Keys (YARA, Hunting)
Detection rules
OpenStrike Beacon Toolkit (172.105.0.126)OpenStrike Shellcode Loader Chain Debug Strings (YARA, Detection); Cobalt Strike 3.x Tripwired ReflectiveLoader + MALC Malleable Profile (YARA, Detection); OpenStrike Python Beacon Ctypes VirtualAlloc Shellcode Injection (SIGMA, Hunting)
Detection rules
Open Directory at 193.56.255.154 — XiebroC2 v3.1 & Covenant C2XiebroC2 v3.1 Go TCP Implant: Source-Code Artifact Combination (YARA, Detection); Covenant PowerShell Fileless Loader: GruntHTTP.ps1 (YARA, Detection); XiebroC2 Go Implant Loading Windows CLR at Runtime via Go-Clr (SIGMA, Detection); PowerShell Fileless Loader: Deflate Decode with Reflective Assembly Load (SIGMA, Hunting)
Detection rules
ZeroTrace Multi-Family MaaS Operation (74.0.42.25)XwormLoader Native Reflective PE Loader (YARA, Detection)
Detection rules
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220)sihost.exe Initiating Anomalous Outbound Network Connection (SIGMA, Detection)
Tracked actors
Designations whose reports map this technique.
- UTA-2026-001: Sliver C2 operator with an automated ScareCrow, Donut and SysWhispers3 build pipeline
- UTA-2026-002: XiebroC2 and Covenant operator working from a Chinese-language build environment
- UTA-2026-004: Developer of the OpenStrike multi-implant C2 toolkit, with a cracked Cobalt Strike arsenal
- UTA-2026-005: Chaos ransomware builder user with a private five-stage crypter
- UTA-2026-006: Stock AdaptixC2 operator with an operator-written PowerShell and .NET injection chain
- UTA-2026-007: HijackLoader customer running a 15-month multi-vector phishing campaign into an AsyncRAT-class RAT
- UTA-2026-016: GHOST cryptojacker kit customer (operator A) with self-hosted mining pool proxies
- UTA-2026-017: GHOST cryptojacker kit customer (operator B) using public mining pools, host abandoned
- UTA-2026-021: Assembler-model intrusion operator staging other actors' tooling against one German victim forest
- UTA-2026-024: Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant
ATT&CK v19.2. MITRE ATT&CK® is a registered trademark of The MITRE Corporation; technique names are MITRE's and link to MITRE's own pages. The mapping on each linked page is this publication's reading of its own evidence.