Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.002 Right-to-Left Override |
GroupFerocious Kitten | Ferocious Kitten has used right-to-left override to reverse executables’ names to make them appear to have different file extensions, rather than their real ones. |
| T1036.002 Right-to-Left Override |
GroupKe3chang | Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files. |
| T1036.002 Right-to-Left Override |
GroupBlackTech | BlackTech has used right-to-left-override to obfuscate the filenames of malicious e-mail attachments. |
| T1036.002 Right-to-Left Override |
GroupBRONZE BUTLER | BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware. |
| T1036.002 Right-to-Left Override |
GroupScarlet Mimic | Scarlet Mimic has used the left-to-right override character in self-extracting RAR archive spearphishing attachment file names. |
| T1036.003 Rename Legitimate Utilities |
GroupAPT38 | APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection. |
| T1036.003 Rename Legitimate Utilities |
GroupGALLIUM | GALLIUM used a renamed cmd.exe file to evade detection. |
| T1036.003 Rename Legitimate Utilities |
GroupmenuPass | menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool. |
| T1036.003 Rename Legitimate Utilities |
GroupAPT32 | APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection. |
| T1036.003 Rename Legitimate Utilities |
GroupLazarus Group | Lazarus Group has renamed system utilities such as |
| T1036.003 Rename Legitimate Utilities |
GroupDaggerfly | Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution. |
| T1036.004 Masquerade Task or Service |
GroupKimsuky | Kimsuky has disguised services to appear as benign software or related to operating system functions. |
| T1036.004 Masquerade Task or Service |
GroupAPT41 | APT41 has created services to appear as benign system tools. |
| T1036.004 Masquerade Task or Service |
GroupAPT32 | APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe". |
| T1036.004 Masquerade Task or Service |
GroupNaikon | Naikon renamed a malicious service |
| T1036.004 Masquerade Task or Service |
GroupFIN6 | FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service. |
| T1036.004 Masquerade Task or Service |
GroupFIN7 | FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence. |
| T1036.004 Masquerade Task or Service |
GroupZIRCONIUM | ZIRCONIUM has created a run key named |
| T1036.004 Masquerade Task or Service |
GroupUNC3886 | UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall. |
| T1036.004 Masquerade Task or Service |
GroupHigaisa | Higaisa named a shellcode loader binary |
| T1036.004 Masquerade Task or Service |
GroupCarbanak | Carbanak has copied legitimate service names to use for malicious services. |
| T1036.004 Masquerade Task or Service |
GroupAquatic Panda | Aquatic Panda created new, malicious services using names such as |
| T1036.004 Masquerade Task or Service |
GroupWinter Vivern | Winter Vivern has distributed malicious scripts and executables mimicking virus scanners. |
| T1036.004 Masquerade Task or Service |
GroupStorm-0501 | Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe. |
| T1036.004 Masquerade Task or Service |
GroupBITTER | BITTER has disguised malware as a Windows Security update service. |
| T1036.004 Masquerade Task or Service |
GroupBackdoorDiplomacy | BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations. |
| T1036.004 Masquerade Task or Service |
GroupFox Kitten | Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate. |
| T1036.004 Masquerade Task or Service |
GroupAPT-C-36 | APT-C-36 has disguised its scheduled tasks as those used by Google. |
| T1036.004 Masquerade Task or Service |
GroupLazarus Group | Lazarus Group has used a scheduled task named `SRCheck` to mask the execution of a malicious .dll. |
| T1036.004 Masquerade Task or Service |
GroupWizard Spider | Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries. |
| T1036.004 Masquerade Task or Service |
GroupVOID MANTICORE | VOID MANTICORE has masqueraded as commonly used programs and services on Windows hosts. |
| T1036.004 Masquerade Task or Service |
GroupPROMETHIUM | PROMETHIUM has named services to appear legitimate. |
| T1036.004 Masquerade Task or Service |
GroupMagic Hound | Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task. |
| T1036.004 Masquerade Task or Service |
GroupFIN13 | FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupIndrik Spider | Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSideCopy | SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustard Tempest | Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKimsuky | Kimsuky has renamed malware to legitimate names such as |
| T1036.005 Match Legitimate Resource Name or Location |
Groupadmin@338 | admin@338 actors used the following command to rename one of their tools to a benign file name: |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVolt Typhoon | Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPatchwork | Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT41 | APT41 attempted to masquerade their files as popular anti-virus software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupmenuPass | menuPass has been seen changing malicious files to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT32 | APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMuddyWater | MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupNaikon | Naikon has disguised malicious programs as Google Chrome, Adobe, and VMware executables. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupGamaredon Group | Gamaredon Group has used legitimate process names to hide malware including |
| T1036.005 Match Legitimate Resource Name or Location |
GroupStorm-1811 | Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamTNT | TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN7 | FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.