Picus Security Explains Advanced Malware Evasion Techniques
Picus Security has detailed the T1497 Virtualization/Sandbox Evasion technique, used by threat actors to detect and bypass security software's controlled environments.

Cybersecurity firm Picus Security has shed light on an advanced malware evasion technique known as T1497 Virtualization/Sandbox Evasion. This method allows attackers to identify and circumvent the virtualized environments and sandboxes commonly employed by security professionals for analysis.
Attackers utilize the T1497 technique to detect environments set up for malware analysis. Upon identification, they can suppress or delay malicious behaviors, enabling attacks to proceed without triggering security controls. This effectively hides malicious activity from defenders.
According to Picus Security's Red Report 2026, T1497 ranked as the fourth most observed technique. Its reappearance in the top observed methods after a two-year absence signals a shift by threat actors towards more stealthy and analysis-aware malware.
The technique encompasses three sub-techniques: System Checks (T1497.001), User Activity Based Checks (T1497.002), and Time Based Checks (T1497.003). Each of these aids the malware in determining whether it is operating within a controlled or a live environment.