Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.001 Invalid Code Signature |
MalwareBADNEWS | BADNEWS is sometimes signed with an invalid Authenticode certificate in an apparent effort to make it look more legitimate. |
| T1036.001 Invalid Code Signature |
MalwareGelsemium | Gelsemium has used unverified signatures on malicious DLLs. |
| T1036.001 Invalid Code Signature |
MalwareSplatCloak | SplatCloak has used a revoked certificate to exploit Windows driver execution policy where certificates issued before a specific date could still load. |
| T1036.001 Invalid Code Signature |
ToolPcShare | PcShare has used an invalid certificate in attempt to appear legitimate. |
| T1036.003 Rename Legitimate Utilities |
MalwareDarkGate | DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the |
| T1036.003 Rename Legitimate Utilities |
MalwareStrelaStealer | StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation. |
| T1036.003 Rename Legitimate Utilities |
MalwarePHASEJAM | PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script. |
| T1036.003 Rename Legitimate Utilities |
MalwareCozyCar | The CozyCar dropper has masqueraded a copy of the infected system's rundll32.exe executable that was moved to the malware's install directory and renamed according to a predefined configuration file. |
| T1036.003 Rename Legitimate Utilities |
MalwareKevin | Kevin has renamed an image of `cmd.exe` with a random name followed by a `.tmpl` extension. |
| T1036.004 Masquerade Task or Service |
MalwareExaramel for Windows | The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV” in an apparent attempt to masquerade as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareStrongPity | StrongPity has named services to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareNebulae | Nebulae has created a service named "Windows Update Agent1" to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareTONESHELL | TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service). |
| T1036.004 Masquerade Task or Service |
MalwareRainyDay | RainyDay has named services and scheduled tasks to appear benign including "ChromeCheck" and "googleupdate." |
| T1036.004 Masquerade Task or Service |
MalwareTinyTurla | TinyTurla has mimicked an existing Windows service by being installed as |
| T1036.004 Masquerade Task or Service |
MalwareBOOKWORM | BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`. |
| T1036.004 Masquerade Task or Service |
MalwareEmotet | Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`. |
| T1036.004 Masquerade Task or Service |
MalwareTurian | Turian can disguise as a legitimate service to blend into normal operations. |
| T1036.004 Masquerade Task or Service |
MalwareMachete | Machete renamed task names to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python tasks. |
| T1036.004 Masquerade Task or Service |
MalwarePingPull | PingPull can mimic the names and descriptions of legitimate services such as `iphlpsvc`, `IP Helper`, and `Onedrive` to evade detection. |
| T1036.004 Masquerade Task or Service |
MalwareHildegard | Hildegard has disguised itself as a known Linux process. |
| T1036.004 Masquerade Task or Service |
MalwareInvisiMole | InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name. |
| T1036.004 Masquerade Task or Service |
MalwareVolgmer | Some Volgmer variants add new services with display names generated by a list of hard-coded strings such as Application, Background, Security, and Windows, presumably as a way to masquerade as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareRDAT | RDAT has used Windows Video Service as a name for malicious services. |
| T1036.004 Masquerade Task or Service |
MalwareOkrum | Okrum can establish persistence by adding a new service NtmsSvc with the display name Removable Storage to masquerade as a legitimate Removable Storage Manager. |
| T1036.004 Masquerade Task or Service |
MalwareRaspberry Robin | Raspberry Robin will execute its payload prior to initializing command and control traffic by impersonating one of several legitimate program names such as dllhost.exe, regsvr32.exe, or rundll32.exe. |
| T1036.004 Masquerade Task or Service |
MalwareFysbis | Fysbis has masqueraded as the rsyncd and dbus-inotifier services. |
| T1036.004 Masquerade Task or Service |
MalwareDCSrv | DCSrv has masqueraded its service as a legitimate svchost.exe process. |
| T1036.004 Masquerade Task or Service |
MalwareShimRat | ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems. |
| T1036.004 Masquerade Task or Service |
MalwareGreen Lambert | Green Lambert has created a new executable named `Software Update Check` to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareGoldMax | GoldMax has impersonated systems management software to avoid detection. |
| T1036.004 Masquerade Task or Service |
MalwarePlugX | In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility." |
| T1036.004 Masquerade Task or Service |
MalwareTruvasys | To establish persistence, Truvasys adds a Registry Run key with a value "TaskMgr" in an attempt to masquerade as the legitimate Windows Task Manager. |
| T1036.004 Masquerade Task or Service |
MalwareSVCReady | SVCReady has named a task `RecoveryExTask` as part of its persistence activity. |
| T1036.004 Masquerade Task or Service |
MalwareUroburos | Uroburos has registered a service named `WerFaultSvc`, likely to spoof the legitimate Windows error reporting service. |
| T1036.004 Masquerade Task or Service |
MalwareSpica | Spica has created a scheduled task named `CalendarChecker` for persistence on compromised hosts. |
| T1036.004 Masquerade Task or Service |
MalwareKONNI | KONNI has pretended to be the xmlProv Network Provisioning service. |
| T1036.004 Masquerade Task or Service |
MalwareShamoon | Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance." |
| T1036.004 Masquerade Task or Service |
MalwareBlack Basta | Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name. |
| T1036.004 Masquerade Task or Service |
MalwareCatchamas | Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareAttor | Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate). |
| T1036.004 Masquerade Task or Service |
MalwareNightClub | NightClub has created a service named `WmdmPmSp` to spoof a Windows Media service. |
| T1036.004 Masquerade Task or Service |
MalwareCrutch | Crutch has established persistence with a scheduled task impersonating the Outlook item finder. |
| T1036.004 Masquerade Task or Service |
MalwareRTM | RTM has named the scheduled task it creates "Windows Update". |
| T1036.004 Masquerade Task or Service |
MalwareRawPOS | New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager". |
| T1036.004 Masquerade Task or Service |
MalwareZxxZ | ZxxZ has been disguised as a Windows security update service. |
| T1036.004 Masquerade Task or Service |
MalwareTarrask | Tarrask creates a scheduled task called “WinUpdate” to re-establish any dropped C2 connections. |
| T1036.004 Masquerade Task or Service |
MalwareBazar | Bazar can create a task named to appear benign. |
| T1036.004 Masquerade Task or Service |
MalwareSUGARDUMP | SUGARDUMP's scheduled task has been named `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` or `MicrosoftEdgeCrashRepoeterTaskMachineUA`, depending on the Windows OS version. |
| T1036.004 Masquerade Task or Service |
MalwareNidiran | Nidiran can create a new service named msamger (Microsoft Security Accounts Manager), which mimics the legitimate Microsoft database by the same name. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.