Real-world descriptions of how a group, tool or campaign used a technique.
143 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCalisto | Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoldenSpy | GoldenSpy's setup file installs initial executables under the folder |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRamsay | Ramsay has masqueraded as a 7zip installer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareAshTag | AshTag has masqueraded as a legitimate VisualServer utility. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCarberp | Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe". |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUNSPOT | SUNSPOT was identified on disk with a filename of |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOutSteel | OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBackConfig | BackConfig has hidden malicious payloads in |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePowGoop | PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLAMEHUG | LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInnaputRAT | InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLookBack | LookBack has a C2 proxy tool that masquerades as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePenquin | Penquin has mimicked the Cron binary to hide itself on compromised systems. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareWinnti for Windows | A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTroll Stealer | Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChChes | ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe). |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareANDROMEDA | ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIceApple | IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShai-Hulud | Shai-Hulud has masqueraded as a legitimate Bun installer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareVIRTUALPITA | VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKOCTOPUS | KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMechaFlounder | MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHTTPBrowser | HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMis-Type | Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOctopus | Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQilin | Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBADNEWS | BADNEWS attempts to hide its payloads using legitimate filenames. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoopy | Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGelsemium | Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOSX/Shlayer | OSX/Shlayer can masquerade as a Flash Player update. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDtrack | One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrifeWater | StrifeWater has been named `calc.exe` to appear as a legitimate calculator program. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareXORIndex Loader | XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSmall Sieve | Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHermeticWizard | HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolShimRatReporter | ShimRatReporter spoofed itself as |
| T1036.005 Match Legitimate Resource Name or Location |
ToolPcShare | PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolBrute Ratel C4 | Brute Ratel C4 has used a payload file named OneDrive.update to appear benign. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolMCMD | MCMD has been named Readme.txt to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCanisterWorm | CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.