Researchers disclosed a sandbox evasion technique that abuses the Intel x86 trap flag (TF) to help malware distinguish physical systems from virtual machines used for analysis. By enabling TF before instructions such as RDTSC, malware can observe whether a debug exception is raised at a different instruction boundary than it would be on real hardware, exposing incorrect hypervisor emulation during a VM exit and allowing the sample to terminate or change behavior before deeper inspection.
The technique was observed in the Lampion malware family, which has targeted users in Portugal, showing that the method is not purely theoretical. Palo Alto Networks said it identified the hypervisor emulation issue in its own environment and deployed a fix so the evasion approach no longer succeeds against WildFire, underscoring the need for defenders to validate sandbox fidelity against low-level CPU and virtualization edge cases.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks identified that incorrect hypervisor emulation of the Intel trap flag could enable this sandbox evasion method and said its hypervisor team tested and deployed a fix. The company stated the specific evasion issue was resolved for malware samples using this technique in WildFire.
The Lampion malware family, which targeted users in Portugal, used an Intel x86 trap-flag single-step check with instructions such as RDTSC and NOP to distinguish virtualized sandboxes from physical machines and terminate when a VM was detected.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.