You underestimate the complexity of malware these days.
Obfuscated to hell, encrypted blocks, tons of loops and rabbit holes that can lead you to dead ends, in addition to malware being more of a bootstrap these days than a self contained application which means it will download additional modules based on the configuration of the machine it has infected and what the mothership tells it to do.
While this might be considered anecdotal I've seen malware that would detect a VM and not disable itself but would pretty bog standard run of the mill post infection modules and perform pretty bog standard post infection tasks (registry entries, auto-run, register a service etc.).
These things are intended to "fool" the researcher into both not understanding the malware and missing its purpose completely and to create false signatures for the file paths, registry entries and binaries all while thinking they've done a great job and call it a day.
The checks that malware does is way beyond simply looking for the usual signs it goes way above dmidecode or systeminfo | grep "insert_hypervisor_name_here".
I've seen malware trying to do a full dump of the bios, access the TPM, try to call various API's that won't really work well in a VM like directx 11, try to get DMA access to various devices, do some timing analysis on IRQ stuff, access the SUPERIO/BIOS functionality for controlling the fans and check if it can control them and what effects it has on the thermals, enumerate how many USB devices are connected pretty much anything you can think off.
So overall I'm pretty amused by the fact that "counting the amount of documents" is considered a "novel evasion technique", it might not even be an evasion technique but just a simple check if this PC is worth infecting or not.
I've seen quite a few cryptolockers infect a machine and only encrypt everything once a certain milestone of "valuable documents" has been reached, some really nasty/cynical ones wait for dates like holidays etc. and wait until you fill your machine with 1000's of photos, or wait for the end of the financial year and wait for you to fill it with tax returns and accounting docs.
P.S.
The cream of the crop isn't malware that is designed to attack users/endpoints, but malware designed to attack servers, so in this case you have to be able to come up with a pretty clever heuristic and or statistical models to figure out if you are running in a researcher's VM or inside a valid target ;)