📣 Send us your press release
Site updates every 15 minutes
Technology

Picus Security Explains Malware's System Check Technique

Picus Security has released an explanation of the T1497.001 System Checks technique within the MITRE ATT&CK framework, detailing how malware identifies its execution environment.

1 October 2026
Picus Security Explains Malware's System Check Technique

Picus Security has published an analysis of the T1497.001 System Checks technique, a sub-technique of Virtualization and Sandbox Evasion (T1497) in the MITRE ATT&CK framework. This technique describes how malware identifies whether it is running on a real endpoint or within a virtual machine or sandbox. Before executing malicious logic, malware collects environmental indicators such as hardware attributes, operating system configuration, and network properties.

Based on this information, malware may alter its behavior to evade detection. Common responses include delaying execution, suppressing payload delivery, terminating the process, or remaining dormant until a more realistic environment is identified. T1497.001 enables adversaries to bypass automated analysis systems and reduce the likelihood of early detection.

The technique leverages indicators pointing to virtual environments, such as disk or BIOS strings, or unusually low CPU core counts. Network adapter MAC address prefixes can also reveal a virtualization platform. Additionally, malware checks for common sandbox hostnames or usernames, as well as registry keys, services, and drivers specific to virtualization software.

The "system check" acts as an "environment gatekeeper." Before performing malicious actions such as installing backdoors or initiating command and control communication, the malware ensures it is operating on a legitimate target rather than in an analyst-controlled sandbox or virtual machine. This strategy has become increasingly prevalent, re-emerging as a key technique in the "Red Report 2026."

Picus Security emphasizes that T1497.001 is a critical component of cyber attack strategies, aimed at disguising malicious activity as a genuine user environment. Organizations must understand this technique to effectively defend their systems.

Original source: picussecurity.com