ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.004×

63 examples

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
MalwareMeteor

Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool.

T1036.004
Masquerade Task or Service
MalwareMaze

Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware.

T1036.004
Masquerade Task or Service
MalwareComRAT

ComRAT has used a task name associated with Windows SQM Consolidator.

T1036.004
Masquerade Task or Service
MalwareVIRTUALPITA

VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services.

T1036.004
Masquerade Task or Service
MalwareHeyoka Backdoor

Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service.

T1036.004
Masquerade Task or Service
MalwareKillDisk

KillDisk registers as a service under the Plug-And-Play Support name.

T1036.004
Masquerade Task or Service
MalwareQilin

Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.

T1036.004
Masquerade Task or Service
MalwarePOWERSTATS

POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence.

T1036.004
Masquerade Task or Service
MalwareDEADWOOD

DEADWOOD will attempt to masquerade its service execution using benign-looking names such as ScDeviceEnums.

T1036.004
Masquerade Task or Service
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose.

T1036.004
Masquerade Task or Service
ToolCSPY Downloader

CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications.

T1036.004
Masquerade Task or Service
ToolIronNetInjector

IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc.

T1036.004
Masquerade Task or Service
MalwareCanisterWorm

CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.