Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupSandworm Team | Sandworm Team has avoided detection by naming a malicious binary explorer.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMachete | Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSidewinder | Sidewinder has named malicious files |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustang Panda | Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRocke | Rocke has used shell scripts which download mining executables and saves them with the filename "java". |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT39 | APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTA2541 | TA2541 has used file names to mimic legitimate Windows files or system functionality. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAkira | Akira has used legitimate names and locations for files to evade defenses. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupOilRig | OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupCarbanak | Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTropic Trooper | Tropic Trooper has hidden payloads in Flash directories and fake installer files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAquatic Panda | Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFerocious Kitten | Ferocious Kitten has named malicious files |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKe3chang | Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT1 | The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBlue Mockingbird | Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTurla | Turla has named components of LunarWeb to mimic Zabbix agent logs. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPoseidon Group | Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRedCurl | RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT29 | APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupChimera | Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBRONZE BUTLER | BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBackdoorDiplomacy | BackdoorDiplomacy has dropped implants in folders named for legitimate software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupDarkhotel | Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEmber Bear | Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupToddyCat | ToddyCat has used the name `debug.exe` for malware components. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWhitefly | Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLuminousMoth | LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT28 | APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT42 | APT42 has masqueraded the VINETHORN payload as a VPN application. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT5 | APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFox Kitten | Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT-C-36 | APT-C-36 has disguised malicious executables to appear as legitimate files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLazarus Group | Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupINC Ransom | INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEarth Lusca | Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSilence | Silence has named its backdoor "WINWORD.exe". |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSowbug | Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVelvet Ant | Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTransparent Tribe | Transparent Tribe can mimic legitimate Windows directories by using the same icons and names. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVOID MANTICORE | VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPROMETHIUM | PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWIRTE | WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMagic Hound | Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN13 | FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamPCP | TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupShinyHunters | ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe. |
| T1036.006 Space after Filename |
GroupAPT38 | APT38 has put several spaces before a file extension to avoid detection and suspicion. |
| T1036.007 Double File Extension |
GroupKimsuky | Kimsuky has used an additional filename extension to hide the true file type. Kimsuky has also masqueraded malicious LNK files as PDF objects using the double extension .pdf.lnk. |
| T1036.007 Double File Extension |
GroupMustang Panda | Mustang Panda has used an additional filename extension to hide the true file type. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.