ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses file naming conventions with associated executable locations to blend in with the macOS TimeMachine and OpenSSL services. Such as, naming a LaunchAgent plist file `com.apple.openssl.plist` which executes OSX_OCEANLOTUS.D from the user's `~/Library/OpenSSL/` folder upon user login.

T1036.004
Masquerade Task or Service
MalwareSeasalt

Seasalt has masqueraded as a service called "SaSaut" with a display name of "System Authorization Service" in an apparent attempt to masquerade as a legitimate service.

T1036.004
Masquerade Task or Service
MalwareFunnyDream

FunnyDream has used a service named `WSearch` for execution.

T1036.004
Masquerade Task or Service
MalwareSysUpdate

SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign.

T1036.004
Masquerade Task or Service
MalwareKwampirs

Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service.

T1036.004
Masquerade Task or Service
MalwareDEADEYE

DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1036.004
Masquerade Task or Service
MalwareInnaputRAT

InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService.

T1036.004
Masquerade Task or Service
MalwareEgregor

Egregor has masqueraded the svchost.exe process to exfiltrate data.

T1036.004
Masquerade Task or Service
Malwarebuild_downer

build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate.

T1036.004
Masquerade Task or Service
MalwareMeteor

Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool.

T1036.004
Masquerade Task or Service
MalwareMaze

Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware.

T1036.004
Masquerade Task or Service
MalwareComRAT

ComRAT has used a task name associated with Windows SQM Consolidator.

T1036.004
Masquerade Task or Service
MalwareVIRTUALPITA

VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services.

T1036.004
Masquerade Task or Service
MalwareHeyoka Backdoor

Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service.

T1036.004
Masquerade Task or Service
MalwareKillDisk

KillDisk registers as a service under the Plug-And-Play Support name.

T1036.004
Masquerade Task or Service
MalwareQilin

Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.

T1036.004
Masquerade Task or Service
MalwarePOWERSTATS

POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence.

T1036.004
Masquerade Task or Service
MalwareDEADWOOD

DEADWOOD will attempt to masquerade its service execution using benign-looking names such as ScDeviceEnums.

T1036.004
Masquerade Task or Service
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose.

T1036.004
Masquerade Task or Service
ToolCSPY Downloader

CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications.

T1036.004
Masquerade Task or Service
ToolIronNetInjector

IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc.

T1036.004
Masquerade Task or Service
MalwareCanisterWorm

CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon.

T1036.005
Match Legitimate Resource Name or Location
MalwareEKANS

EKANS has been disguised as update.exe to appear as a valid executable.

T1036.005
Match Legitimate Resource Name or Location
MalwareBLINDINGCAN

BLINDINGCAN has attempted to hide its payload by using legitimate file names such as "iconcache.db".

T1036.005
Match Legitimate Resource Name or Location
MalwareNinja

Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll.

T1036.005
Match Legitimate Resource Name or Location
MalwareBumblebee

Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer.

T1036.005
Match Legitimate Resource Name or Location
MalwareBRICKSTORM

BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`.

T1036.005
Match Legitimate Resource Name or Location
MalwareNOKKI

NOKKI is written to %LOCALAPPDATA%\MicroSoft Updatea\svServiceUpdate.exe prior being executed in a new process in an apparent attempt to masquerade as a legitimate folder and file.

T1036.005
Match Legitimate Resource Name or Location
MalwareRotaJakiro

RotaJakiro has used the filename `systemd-daemon` in an attempt to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareChinoxy

Chinoxy has used the name `eoffice.exe` in attempt to appear as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
MalwareMisdat

Misdat saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareUrsnif

Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names.

T1036.005
Match Legitimate Resource Name or Location
MalwareThreatNeedle

ThreatNeedle chooses its payload creation path from a randomly selected service name from netsvc.

T1036.005
Match Legitimate Resource Name or Location
MalwareZLib

ZLib mimics the resource version information of legitimate Realtek Semiconductor, Nvidia, or Synaptics modules.

T1036.005
Match Legitimate Resource Name or Location
MalwareTsundere Botnet

Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software.

T1036.005
Match Legitimate Resource Name or Location
MalwareFelismus

Felismus has masqueraded as legitimate Adobe Content Management System files.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrongPity

StrongPity has been bundled with legitimate software installation files for disguise.

T1036.005
Match Legitimate Resource Name or Location
MalwareNebulae

Nebulae uses functions named StartUserModeBrowserInjection and StopUserModeBrowserInjection indicating that it's trying to imitate chrome_frame_helper.dll.

T1036.005
Match Legitimate Resource Name or Location
MalwareTONESHELL

TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll.

T1036.005
Match Legitimate Resource Name or Location
MalwareRainyDay

RainyDay has used names to mimic legitimate software including "vmtoolsd.exe" to spoof Vmtools.

T1036.005
Match Legitimate Resource Name or Location
MalwareAppleSeed

AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity.

T1036.005
Match Legitimate Resource Name or Location
MalwareNETWIRE

NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder.

T1036.005
Match Legitimate Resource Name or Location
MalwareTinyTurla

TinyTurla has been deployed as `w64time.dll` to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwarePyDCrypt

PyDCrypt has dropped DCSrv under the `svchost.exe` name to disk.

T1036.005
Match Legitimate Resource Name or Location
MalwareJ-magic

J-magic can rename itself as “[nfsiod 0]” to masquerade as the local Network File System (NFS) asynchronous I/O server.

T1036.005
Match Legitimate Resource Name or Location
MalwareOLDBAIT

OLDBAIT installs itself in %ALLUSERPROFILE%\\Application Data\Microsoft\MediaPlayer\updatewindws.exe; the directory name is missing a space and the file name is missing the letter "o."

T1036.005
Match Legitimate Resource Name or Location
MalwareBad Rabbit

Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1036.005
Match Legitimate Resource Name or Location
MalwareSTATICPLUGIN

STATICPLUGIN has leveraged naming conventions that match legitimate services to include AdobePlugins.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareTEARDROP

TEARDROP files had names that resembled legitimate Window file and directory names.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.