ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.005×

63 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupIndrik Spider

Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors.

T1036.005
Match Legitimate Resource Name or Location
GroupSideCopy

SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool.

T1036.005
Match Legitimate Resource Name or Location
GroupMustard Tempest

Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`.

T1036.005
Match Legitimate Resource Name or Location
GroupKimsuky

Kimsuky has renamed malware to legitimate names such as ESTCommon.dll or patch.dll. Kimsuky has also disguised payloads using legitimate file names including a PowerShell payload named chrome.ps1. Kimsuky has also used a malicious QR code that masqueraded as a legitimate package delivery service.

T1036.005
Match Legitimate Resource Name or Location
Groupadmin@338

admin@338 actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe

T1036.005
Match Legitimate Resource Name or Location
GroupVolt Typhoon

Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.

T1036.005
Match Legitimate Resource Name or Location
GroupPatchwork

Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT41

APT41 attempted to masquerade their files as popular anti-virus software.

T1036.005
Match Legitimate Resource Name or Location
GroupmenuPass

menuPass has been seen changing malicious files to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT32

APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupMuddyWater

MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender.

T1036.005
Match Legitimate Resource Name or Location
GroupNaikon

Naikon has disguised malicious programs as Google Chrome, Adobe, and VMware executables.

T1036.005
Match Legitimate Resource Name or Location
GroupGamaredon Group

Gamaredon Group has used legitimate process names to hide malware including svchosst. Additionally, Gamaredon Group disguised malicious ZIP archives as Office documents that are related to the invasion.

T1036.005
Match Legitimate Resource Name or Location
GroupStorm-1811

Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package.

T1036.005
Match Legitimate Resource Name or Location
GroupTeamTNT

TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software.

T1036.005
Match Legitimate Resource Name or Location
GroupFIN7

FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name.

T1036.005
Match Legitimate Resource Name or Location
GroupSandworm Team

Sandworm Team has avoided detection by naming a malicious binary explorer.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupMachete

Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer.

T1036.005
Match Legitimate Resource Name or Location
GroupSidewinder

Sidewinder has named malicious files rekeywiz.exe to match the name of a legitimate Windows executable.

T1036.005
Match Legitimate Resource Name or Location
GroupMustang Panda

Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupRocke

Rocke has used shell scripts which download mining executables and saves them with the filename "java".

T1036.005
Match Legitimate Resource Name or Location
GroupAPT39

APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupTA2541

TA2541 has used file names to mimic legitimate Windows files or system functionality.

T1036.005
Match Legitimate Resource Name or Location
GroupAkira

Akira has used legitimate names and locations for files to evade defenses.

T1036.005
Match Legitimate Resource Name or Location
GroupOilRig

OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupCarbanak

Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program.

T1036.005
Match Legitimate Resource Name or Location
GroupTropic Trooper

Tropic Trooper has hidden payloads in Flash directories and fake installer files.

T1036.005
Match Legitimate Resource Name or Location
GroupAquatic Panda

Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments.

T1036.005
Match Legitimate Resource Name or Location
GroupFerocious Kitten

Ferocious Kitten has named malicious files update.exe and loaded them into the compromise host's “Public” folder.

T1036.005
Match Legitimate Resource Name or Location
GroupKe3chang

Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT1

The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware.

T1036.005
Match Legitimate Resource Name or Location
GroupBlue Mockingbird

Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file.

T1036.005
Match Legitimate Resource Name or Location
GroupTurla

Turla has named components of LunarWeb to mimic Zabbix agent logs.

T1036.005
Match Legitimate Resource Name or Location
GroupPoseidon Group

Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense.

T1036.005
Match Legitimate Resource Name or Location
GroupRedCurl

RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and
`MdMMaintenenceTask` to mask malicious files and scheduled tasks.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT29

APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal.

T1036.005
Match Legitimate Resource Name or Location
GroupChimera

Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupBRONZE BUTLER

BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems.

T1036.005
Match Legitimate Resource Name or Location
GroupBackdoorDiplomacy

BackdoorDiplomacy has dropped implants in folders named for legitimate software.

T1036.005
Match Legitimate Resource Name or Location
GroupDarkhotel

Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool.

T1036.005
Match Legitimate Resource Name or Location
GroupEmber Bear

Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments.

T1036.005
Match Legitimate Resource Name or Location
GroupToddyCat

ToddyCat has used the name `debug.exe` for malware components.

T1036.005
Match Legitimate Resource Name or Location
GroupWhitefly

Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors.

T1036.005
Match Legitimate Resource Name or Location
GroupLuminousMoth

LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT28

APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT42

APT42 has masqueraded the VINETHORN payload as a VPN application.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT5

APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern.

T1036.005
Match Legitimate Resource Name or Location
GroupFox Kitten

Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT-C-36

APT-C-36 has disguised malicious executables to appear as legitimate files.

T1036.005
Match Legitimate Resource Name or Location
GroupLazarus Group

Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.