MITRE ATT&CK Technique
T1497.003Time Based Checks
- First Reported
- Aug 26, 2026
- Latest Reported
- Sep 30, 2026
Official Description
Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time. This may include enumerating time-based properties, such as uptime or the system clock.
Adversaries may use calls like `GetTickCount` and `GetSystemTimeAsFileTime` to discover if they are operating within a virtual machine or sandbox, or may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.(Citation: ISACA Malware Tricks)
Adversaries may use calls like `GetTickCount` and `GetSystemTimeAsFileTime` to discover if they are operating within a virtual machine or sandbox, or may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.(Citation: ISACA Malware Tricks)
- Tactics
- Stealth, Discovery
- Platforms
- Linux, macOS, Windows
- Parent Technique
- T1497 · Virtualization/Sandbox Evasion
- MITRE Version
- 3.0
- Last Modified
- May 12, 2026
Reported Context (3)
- 2CLoader uses CPU-cycle and elapsed-time checks intended to affect execution in emulated or analyzed environments. 2CLoader Malware Loader Uses Evasion and Injection to Deliver Vidar and Remus
- The NetSupport installation script checked system uptime and measured whether a native delay elapsed as expected. ClearFake WebDAV Chains Deliver Amatera, ZigCryptoStealer and Unauthorized NetSupport
- The loader checked elapsed sleep time and terminated if timing suggested a manipulated analysis environment. Cambodia-Focused Malware Campaign Uses Multi-Stage Infection Chain and SparkRAT
CVE (1)
Malware (8)
Threat Actors (2)
MITRE ATT&CK (25)
Vendors (7)
Products (12)
Tools (3)
Industries (1)
Countries (8)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.