Real-world descriptions of how a group, tool or campaign used a technique.
63 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
MalwareExaramel for Windows | The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV” in an apparent attempt to masquerade as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareStrongPity | StrongPity has named services to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareNebulae | Nebulae has created a service named "Windows Update Agent1" to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareTONESHELL | TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service). |
| T1036.004 Masquerade Task or Service |
MalwareRainyDay | RainyDay has named services and scheduled tasks to appear benign including "ChromeCheck" and "googleupdate." |
| T1036.004 Masquerade Task or Service |
MalwareTinyTurla | TinyTurla has mimicked an existing Windows service by being installed as |
| T1036.004 Masquerade Task or Service |
MalwareBOOKWORM | BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`. |
| T1036.004 Masquerade Task or Service |
MalwareEmotet | Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`. |
| T1036.004 Masquerade Task or Service |
MalwareTurian | Turian can disguise as a legitimate service to blend into normal operations. |
| T1036.004 Masquerade Task or Service |
MalwareMachete | Machete renamed task names to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python tasks. |
| T1036.004 Masquerade Task or Service |
MalwarePingPull | PingPull can mimic the names and descriptions of legitimate services such as `iphlpsvc`, `IP Helper`, and `Onedrive` to evade detection. |
| T1036.004 Masquerade Task or Service |
MalwareHildegard | Hildegard has disguised itself as a known Linux process. |
| T1036.004 Masquerade Task or Service |
MalwareInvisiMole | InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name. |
| T1036.004 Masquerade Task or Service |
MalwareVolgmer | Some Volgmer variants add new services with display names generated by a list of hard-coded strings such as Application, Background, Security, and Windows, presumably as a way to masquerade as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareRDAT | RDAT has used Windows Video Service as a name for malicious services. |
| T1036.004 Masquerade Task or Service |
MalwareOkrum | Okrum can establish persistence by adding a new service NtmsSvc with the display name Removable Storage to masquerade as a legitimate Removable Storage Manager. |
| T1036.004 Masquerade Task or Service |
MalwareRaspberry Robin | Raspberry Robin will execute its payload prior to initializing command and control traffic by impersonating one of several legitimate program names such as dllhost.exe, regsvr32.exe, or rundll32.exe. |
| T1036.004 Masquerade Task or Service |
MalwareFysbis | Fysbis has masqueraded as the rsyncd and dbus-inotifier services. |
| T1036.004 Masquerade Task or Service |
MalwareDCSrv | DCSrv has masqueraded its service as a legitimate svchost.exe process. |
| T1036.004 Masquerade Task or Service |
MalwareShimRat | ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems. |
| T1036.004 Masquerade Task or Service |
MalwareGreen Lambert | Green Lambert has created a new executable named `Software Update Check` to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareGoldMax | GoldMax has impersonated systems management software to avoid detection. |
| T1036.004 Masquerade Task or Service |
MalwarePlugX | In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility." |
| T1036.004 Masquerade Task or Service |
MalwareTruvasys | To establish persistence, Truvasys adds a Registry Run key with a value "TaskMgr" in an attempt to masquerade as the legitimate Windows Task Manager. |
| T1036.004 Masquerade Task or Service |
MalwareSVCReady | SVCReady has named a task `RecoveryExTask` as part of its persistence activity. |
| T1036.004 Masquerade Task or Service |
MalwareUroburos | Uroburos has registered a service named `WerFaultSvc`, likely to spoof the legitimate Windows error reporting service. |
| T1036.004 Masquerade Task or Service |
MalwareSpica | Spica has created a scheduled task named `CalendarChecker` for persistence on compromised hosts. |
| T1036.004 Masquerade Task or Service |
MalwareKONNI | KONNI has pretended to be the xmlProv Network Provisioning service. |
| T1036.004 Masquerade Task or Service |
MalwareShamoon | Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance." |
| T1036.004 Masquerade Task or Service |
MalwareBlack Basta | Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name. |
| T1036.004 Masquerade Task or Service |
MalwareCatchamas | Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareAttor | Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate). |
| T1036.004 Masquerade Task or Service |
MalwareNightClub | NightClub has created a service named `WmdmPmSp` to spoof a Windows Media service. |
| T1036.004 Masquerade Task or Service |
MalwareCrutch | Crutch has established persistence with a scheduled task impersonating the Outlook item finder. |
| T1036.004 Masquerade Task or Service |
MalwareRTM | RTM has named the scheduled task it creates "Windows Update". |
| T1036.004 Masquerade Task or Service |
MalwareRawPOS | New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager". |
| T1036.004 Masquerade Task or Service |
MalwareZxxZ | ZxxZ has been disguised as a Windows security update service. |
| T1036.004 Masquerade Task or Service |
MalwareTarrask | Tarrask creates a scheduled task called “WinUpdate” to re-establish any dropped C2 connections. |
| T1036.004 Masquerade Task or Service |
MalwareBazar | Bazar can create a task named to appear benign. |
| T1036.004 Masquerade Task or Service |
MalwareSUGARDUMP | SUGARDUMP's scheduled task has been named `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` or `MicrosoftEdgeCrashRepoeterTaskMachineUA`, depending on the Windows OS version. |
| T1036.004 Masquerade Task or Service |
MalwareNidiran | Nidiran can create a new service named msamger (Microsoft Security Accounts Manager), which mimics the legitimate Microsoft database by the same name. |
| T1036.004 Masquerade Task or Service |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses file naming conventions with associated executable locations to blend in with the macOS TimeMachine and OpenSSL services. Such as, naming a LaunchAgent plist file `com.apple.openssl.plist` which executes OSX_OCEANLOTUS.D from the user's `~/Library/OpenSSL/` folder upon user login. |
| T1036.004 Masquerade Task or Service |
MalwareSeasalt | Seasalt has masqueraded as a service called "SaSaut" with a display name of "System Authorization Service" in an apparent attempt to masquerade as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareFunnyDream | FunnyDream has used a service named `WSearch` for execution. |
| T1036.004 Masquerade Task or Service |
MalwareSysUpdate | SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign. |
| T1036.004 Masquerade Task or Service |
MalwareKwampirs | Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service. |
| T1036.004 Masquerade Task or Service |
MalwareDEADEYE | DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1036.004 Masquerade Task or Service |
MalwareInnaputRAT | InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService. |
| T1036.004 Masquerade Task or Service |
MalwareEgregor | Egregor has masqueraded the svchost.exe process to exfiltrate data. |
| T1036.004 Masquerade Task or Service |
Malwarebuild_downer | build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.