Real-world descriptions of how a group, tool or campaign used a technique.
63 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
MalwareMeteor | Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool. |
| T1036.004 Masquerade Task or Service |
MalwareMaze | Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware. |
| T1036.004 Masquerade Task or Service |
MalwareComRAT | ComRAT has used a task name associated with Windows SQM Consolidator. |
| T1036.004 Masquerade Task or Service |
MalwareVIRTUALPITA | VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services. |
| T1036.004 Masquerade Task or Service |
MalwareHeyoka Backdoor | Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareKillDisk | KillDisk registers as a service under the Plug-And-Play Support name. |
| T1036.004 Masquerade Task or Service |
MalwareQilin | Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer. |
| T1036.004 Masquerade Task or Service |
MalwarePOWERSTATS | POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence. |
| T1036.004 Masquerade Task or Service |
MalwareDEADWOOD | DEADWOOD will attempt to masquerade its service execution using benign-looking names such as |
| T1036.004 Masquerade Task or Service |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose. |
| T1036.004 Masquerade Task or Service |
ToolCSPY Downloader | CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications. |
| T1036.004 Masquerade Task or Service |
ToolIronNetInjector | IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc. |
| T1036.004 Masquerade Task or Service |
MalwareCanisterWorm | CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.