Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses file naming conventions with associated executable locations to blend in with the macOS TimeMachine and OpenSSL services. Such as, naming a LaunchAgent plist file `com.apple.openssl.plist` which executes OSX_OCEANLOTUS.D from the user's `~/Library/OpenSSL/` folder upon user login. |
| T1036.004 Masquerade Task or Service |
MalwareSeasalt | Seasalt has masqueraded as a service called "SaSaut" with a display name of "System Authorization Service" in an apparent attempt to masquerade as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareFunnyDream | FunnyDream has used a service named `WSearch` for execution. |
| T1036.004 Masquerade Task or Service |
MalwareSysUpdate | SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign. |
| T1036.004 Masquerade Task or Service |
MalwareKwampirs | Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service. |
| T1036.004 Masquerade Task or Service |
MalwareDEADEYE | DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1036.004 Masquerade Task or Service |
MalwareInnaputRAT | InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService. |
| T1036.004 Masquerade Task or Service |
MalwareEgregor | Egregor has masqueraded the svchost.exe process to exfiltrate data. |
| T1036.004 Masquerade Task or Service |
Malwarebuild_downer | build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareMeteor | Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool. |
| T1036.004 Masquerade Task or Service |
MalwareMaze | Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware. |
| T1036.004 Masquerade Task or Service |
MalwareComRAT | ComRAT has used a task name associated with Windows SQM Consolidator. |
| T1036.004 Masquerade Task or Service |
MalwareVIRTUALPITA | VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services. |
| T1036.004 Masquerade Task or Service |
MalwareHeyoka Backdoor | Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareKillDisk | KillDisk registers as a service under the Plug-And-Play Support name. |
| T1036.004 Masquerade Task or Service |
MalwareQilin | Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer. |
| T1036.004 Masquerade Task or Service |
MalwarePOWERSTATS | POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence. |
| T1036.004 Masquerade Task or Service |
MalwareDEADWOOD | DEADWOOD will attempt to masquerade its service execution using benign-looking names such as |
| T1036.004 Masquerade Task or Service |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose. |
| T1036.004 Masquerade Task or Service |
ToolCSPY Downloader | CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications. |
| T1036.004 Masquerade Task or Service |
ToolIronNetInjector | IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc. |
| T1036.004 Masquerade Task or Service |
MalwareCanisterWorm | CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareEKANS | EKANS has been disguised as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBLINDINGCAN | BLINDINGCAN has attempted to hide its payload by using legitimate file names such as "iconcache.db". |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNinja | Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBumblebee | Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBRICKSTORM | BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNOKKI | NOKKI is written to %LOCALAPPDATA%\MicroSoft Updatea\svServiceUpdate.exe prior being executed in a new process in an apparent attempt to masquerade as a legitimate folder and file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRotaJakiro | RotaJakiro has used the filename `systemd-daemon` in an attempt to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChinoxy | Chinoxy has used the name `eoffice.exe` in attempt to appear as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMisdat | Misdat saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareUrsnif | Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareThreatNeedle | ThreatNeedle chooses its payload creation path from a randomly selected service name from netsvc. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareZLib | ZLib mimics the resource version information of legitimate Realtek Semiconductor, Nvidia, or Synaptics modules. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTsundere Botnet | Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFelismus | Felismus has masqueraded as legitimate Adobe Content Management System files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrongPity | StrongPity has been bundled with legitimate software installation files for disguise. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNebulae | Nebulae uses functions named |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTONESHELL | TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRainyDay | RainyDay has used names to mimic legitimate software including "vmtoolsd.exe" to spoof Vmtools. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareAppleSeed | AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNETWIRE | NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTinyTurla | TinyTurla has been deployed as `w64time.dll` to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePyDCrypt | PyDCrypt has dropped DCSrv under the `svchost.exe` name to disk. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareJ-magic | J-magic can rename itself as “[nfsiod 0]” to masquerade as the local Network File System (NFS) asynchronous I/O server. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOLDBAIT | OLDBAIT installs itself in |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBad Rabbit | Bad Rabbit has masqueraded as a Flash Player installer through the executable file |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSTATICPLUGIN | STATICPLUGIN has leveraged naming conventions that match legitimate services to include AdobePlugins.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTEARDROP | TEARDROP files had names that resembled legitimate Window file and directory names. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.