Real-world descriptions of how a group, tool or campaign used a technique.
63 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupIndrik Spider | Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSideCopy | SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustard Tempest | Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKimsuky | Kimsuky has renamed malware to legitimate names such as |
| T1036.005 Match Legitimate Resource Name or Location |
Groupadmin@338 | admin@338 actors used the following command to rename one of their tools to a benign file name: |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVolt Typhoon | Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPatchwork | Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT41 | APT41 attempted to masquerade their files as popular anti-virus software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupmenuPass | menuPass has been seen changing malicious files to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT32 | APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMuddyWater | MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupNaikon | Naikon has disguised malicious programs as Google Chrome, Adobe, and VMware executables. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupGamaredon Group | Gamaredon Group has used legitimate process names to hide malware including |
| T1036.005 Match Legitimate Resource Name or Location |
GroupStorm-1811 | Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamTNT | TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN7 | FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSandworm Team | Sandworm Team has avoided detection by naming a malicious binary explorer.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMachete | Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSidewinder | Sidewinder has named malicious files |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustang Panda | Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRocke | Rocke has used shell scripts which download mining executables and saves them with the filename "java". |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT39 | APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTA2541 | TA2541 has used file names to mimic legitimate Windows files or system functionality. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAkira | Akira has used legitimate names and locations for files to evade defenses. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupOilRig | OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupCarbanak | Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTropic Trooper | Tropic Trooper has hidden payloads in Flash directories and fake installer files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAquatic Panda | Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFerocious Kitten | Ferocious Kitten has named malicious files |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKe3chang | Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT1 | The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBlue Mockingbird | Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTurla | Turla has named components of LunarWeb to mimic Zabbix agent logs. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPoseidon Group | Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRedCurl | RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT29 | APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupChimera | Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBRONZE BUTLER | BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBackdoorDiplomacy | BackdoorDiplomacy has dropped implants in folders named for legitimate software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupDarkhotel | Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEmber Bear | Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupToddyCat | ToddyCat has used the name `debug.exe` for malware components. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWhitefly | Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLuminousMoth | LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT28 | APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT42 | APT42 has masqueraded the VINETHORN payload as a VPN application. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT5 | APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFox Kitten | Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT-C-36 | APT-C-36 has disguised malicious executables to appear as legitimate files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLazarus Group | Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.