Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036 Masquerading |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document. |
| T1036 Masquerading |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors disguised some executables as JPG files. |
| T1036 Masquerading |
CampaignC0018 | During C0018, AvosLocker was disguised using the victim company name as the filename. |
| T1036 Masquerading |
CampaignC0015 | During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file. |
| T1036 Masquerading |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used voice calls to socially engineer victims into authorizing a modified version of the Salesforce Data Loader app. |
| T1036 Masquerading |
CampaignArcaneDoor | ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances. |
| T1036.004 Masquerade Task or Service |
CampaignKV Botnet Activity | KV Botnet Activity installation steps include first identifying, then stopping, any process containing |
| T1036.004 Masquerade Task or Service |
CampaignFrankenstein | During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence. |
| T1036.004 Masquerade Task or Service |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda masqueraded Registry run keys as legitimate-looking service names such as `OneNote Update` during RedDelta Modified PlugX Infection Chain Operations. |
| T1036.004 Masquerade Task or Service |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate. |
| T1036.004 Masquerade Task or Service |
CampaignAPT41 DUST | APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1036.004 Masquerade Task or Service |
CampaignC0017 | During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code. |
| T1036.004 Masquerade Task or Service |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Systemd service units to masquerade GOGETTER malware as legitimate or seemingly legitimate services. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignRedPenguin | During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Sharpshooter | During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0018 | For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignHomeLand Justice | During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0032 | During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files. |
| T1036.005 Match Legitimate Resource Name or Location |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Wocao | During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0017 | During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections. |
| T1036.008 Masquerade File Type |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection. |
| T1036.008 Masquerade File Type |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files. |
| T1036.008 Masquerade File Type |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as `.txt` files. |
| T1036.010 Masquerade Account Name |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). |
| T1037 Boot or Logon Initialization Scripts |
CampaignArcaneDoor | ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices. |
| T1039 Data from Network Shared Drive |
CampaignC0015 | During C0015, the threat actors collected files from network shared drives prior to network encryption. |
| T1040 Network Sniffing |
CampaignRedPenguin | During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer. |
| T1040 Network Sniffing |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network between the local LAN and the power grid’s industrial control systems. |
| T1040 Network Sniffing |
CampaignArcaneDoor | ArcaneDoor included network packet capture and sniffing for data collection in victim environments. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure. |
| T1041 Exfiltration Over C2 Channel |
CampaignFrankenstein | During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2. |
| T1041 Exfiltration Over C2 Channel |
CampaignRedPenguin | During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers. |
| T1041 Exfiltration Over C2 Channel |
CampaignArcaneDoor | ArcaneDoor included use of existing command and control channels for data exfiltration. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Wocao | During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data. |
| T1041 Exfiltration Over C2 Channel |
CampaignLeviathan Australian Intrusions | Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions. |
| T1041 Exfiltration Over C2 Channel |
CampaignC0017 | During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration. |
| T1046 Network Service Discovery |
CampaignC0018 | During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning. |
| T1046 Network Service Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to enumerate internal network services and endpoints across targeted environments using browser automation via MCP, including databases, container registries, admin interfaces, and workflow orchestration platforms. |
| T1046 Network Service Discovery |
CampaignHomeLand Justice | During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.