ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupSandworm Team

Sandworm Team has avoided detection by naming a malicious binary explorer.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupMachete

Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer.

T1036.005
Match Legitimate Resource Name or Location
GroupSidewinder

Sidewinder has named malicious files rekeywiz.exe to match the name of a legitimate Windows executable.

T1036.005
Match Legitimate Resource Name or Location
GroupMustang Panda

Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupRocke

Rocke has used shell scripts which download mining executables and saves them with the filename "java".

T1036.005
Match Legitimate Resource Name or Location
GroupAPT39

APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupTA2541

TA2541 has used file names to mimic legitimate Windows files or system functionality.

T1036.005
Match Legitimate Resource Name or Location
GroupAkira

Akira has used legitimate names and locations for files to evade defenses.

T1036.005
Match Legitimate Resource Name or Location
GroupOilRig

OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupCarbanak

Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program.

T1036.005
Match Legitimate Resource Name or Location
GroupTropic Trooper

Tropic Trooper has hidden payloads in Flash directories and fake installer files.

T1036.005
Match Legitimate Resource Name or Location
GroupAquatic Panda

Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments.

T1036.005
Match Legitimate Resource Name or Location
GroupFerocious Kitten

Ferocious Kitten has named malicious files update.exe and loaded them into the compromise host's “Public” folder.

T1036.005
Match Legitimate Resource Name or Location
GroupKe3chang

Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT1

The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware.

T1036.005
Match Legitimate Resource Name or Location
GroupBlue Mockingbird

Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file.

T1036.005
Match Legitimate Resource Name or Location
GroupTurla

Turla has named components of LunarWeb to mimic Zabbix agent logs.

T1036.005
Match Legitimate Resource Name or Location
GroupPoseidon Group

Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense.

T1036.005
Match Legitimate Resource Name or Location
GroupRedCurl

RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and
`MdMMaintenenceTask` to mask malicious files and scheduled tasks.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT29

APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal.

T1036.005
Match Legitimate Resource Name or Location
GroupChimera

Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupBRONZE BUTLER

BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems.

T1036.005
Match Legitimate Resource Name or Location
GroupBackdoorDiplomacy

BackdoorDiplomacy has dropped implants in folders named for legitimate software.

T1036.005
Match Legitimate Resource Name or Location
GroupDarkhotel

Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool.

T1036.005
Match Legitimate Resource Name or Location
GroupEmber Bear

Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments.

T1036.005
Match Legitimate Resource Name or Location
GroupToddyCat

ToddyCat has used the name `debug.exe` for malware components.

T1036.005
Match Legitimate Resource Name or Location
GroupWhitefly

Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors.

T1036.005
Match Legitimate Resource Name or Location
GroupLuminousMoth

LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT28

APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT42

APT42 has masqueraded the VINETHORN payload as a VPN application.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT5

APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern.

T1036.005
Match Legitimate Resource Name or Location
GroupFox Kitten

Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT-C-36

APT-C-36 has disguised malicious executables to appear as legitimate files.

T1036.005
Match Legitimate Resource Name or Location
GroupLazarus Group

Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files.

T1036.005
Match Legitimate Resource Name or Location
GroupINC Ransom

INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.

T1036.005
Match Legitimate Resource Name or Location
GroupEarth Lusca

Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service.

T1036.005
Match Legitimate Resource Name or Location
GroupSilence

Silence has named its backdoor "WINWORD.exe".

T1036.005
Match Legitimate Resource Name or Location
GroupSowbug

Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory CSIDL_APPDATA\microsoft\security.

T1036.005
Match Legitimate Resource Name or Location
GroupVelvet Ant

Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows.

T1036.005
Match Legitimate Resource Name or Location
GroupTransparent Tribe

Transparent Tribe can mimic legitimate Windows directories by using the same icons and names.

T1036.005
Match Legitimate Resource Name or Location
GroupVOID MANTICORE

VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram.

T1036.005
Match Legitimate Resource Name or Location
GroupPROMETHIUM

PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers.

T1036.005
Match Legitimate Resource Name or Location
GroupWIRTE

WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupMagic Hound

Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink.

T1036.005
Match Legitimate Resource Name or Location
GroupFIN13

FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war.

T1036.005
Match Legitimate Resource Name or Location
GroupTeamPCP

TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.

T1036.005
Match Legitimate Resource Name or Location
GroupShinyHunters

ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.

T1036.006
Space after Filename
GroupAPT38

APT38 has put several spaces before a file extension to avoid detection and suspicion.

T1036.007
Double File Extension
GroupKimsuky

Kimsuky has used an additional filename extension to hide the true file type. Kimsuky has also masqueraded malicious LNK files as PDF objects using the double extension .pdf.lnk.

T1036.007
Double File Extension
GroupMustang Panda

Mustang Panda has used an additional filename extension to hide the true file type.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.