ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareStrelaStealer

StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company.

T1036.005
Match Legitimate Resource Name or Location
MalwareGrandoreiro

Grandoreiro has named malicious browser extensions and update files to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareStarloader

Starloader has masqueraded as legitimate software update packages such as Adobe Acrobat Reader and Intel.

T1036.005
Match Legitimate Resource Name or Location
MalwareSibot

Sibot has downloaded a DLL to the C:\windows\system32\drivers\ folder and renamed it with a .sys extension.

T1036.005
Match Legitimate Resource Name or Location
MalwareTarrask

Tarrask has masqueraded as executable files such as `winupdate.exe`, `date.exe`, or `win.exe`.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoBear

GoBear is installed through droppers masquerading as legitimate, signed software installers.

T1036.005
Match Legitimate Resource Name or Location
MalwareShark

Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareBazar

The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUGARDUMP

SUGARDUMP has been named `CrashReporter.exe` to appear as a legitimate Mozilla executable.

T1036.005
Match Legitimate Resource Name or Location
MalwareRyuk

Ryuk has constructed legitimate appearing installation folder paths by calling GetWindowsDirectoryW and then inserting a null byte at the fourth character of the path. For Windows Vista or higher, the path would appear as C:\Users\Public.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWiper

HermeticWiper has used the name `postgressql.exe` to mask a malicious payload.

T1036.005
Match Legitimate Resource Name or Location
MalwarePysa

Pysa has executed a malicious executable by naming it svchost.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareFinFisher

FinFisher renames one of its .dll files to uxtheme.dll in an apparent attempt to masquerade as a legitimate file.

T1036.005
Match Legitimate Resource Name or Location
MalwareOwaAuth

OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\Auth\; the malicious file by the same name is saved in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\bin\.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUNBURST

SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities.

T1036.005
Match Legitimate Resource Name or Location
MalwareREvil

REvil can mimic the names of known executables.

T1036.005
Match Legitimate Resource Name or Location
MalwareSamurai

Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages.

T1036.005
Match Legitimate Resource Name or Location
MalwareUSBStealer

USBStealer mimics a legitimate Russian program called USB Disk Security.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUPERNOVA

SUPERNOVA has masqueraded as a legitimate SolarWinds DLL.

T1036.005
Match Legitimate Resource Name or Location
MalwareCyclops Blink

Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread. Cyclops Blink has also named RC scripts used for persistence after WatchGuard artifacts.

T1036.005
Match Legitimate Resource Name or Location
MalwareDaserf

Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs.

T1036.005
Match Legitimate Resource Name or Location
MalwareDanBot

DanBot files have been named `UltraVNC.exe` and `WINVNC.exe` to appear as legitimate VNC tools.

T1036.005
Match Legitimate Resource Name or Location
MalwareCalisto

Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoldenSpy

GoldenSpy's setup file installs initial executables under the folder %WinDir%\System32\PluginManager.

T1036.005
Match Legitimate Resource Name or Location
MalwareRamsay

Ramsay has masqueraded as a 7zip installer.

T1036.005
Match Legitimate Resource Name or Location
MalwareAshTag

AshTag has masqueraded as a legitimate VisualServer utility.

T1036.005
Match Legitimate Resource Name or Location
MalwareCarberp

Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe".

T1036.005
Match Legitimate Resource Name or Location
MalwareSUNSPOT

SUNSPOT was identified on disk with a filename of taskhostsvc.exe and it created an encrypted log file at C:\Windows\Temp\vmware-vmdmp.log.

T1036.005
Match Legitimate Resource Name or Location
MalwareOutSteel

OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: %TEMP%\\svjhost.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareBackConfig

BackConfig has hidden malicious payloads in %USERPROFILE%\Adobe\Driver\dwg\ and mimicked the legitimate DHCP service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwarePowGoop

PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file.

T1036.005
Match Legitimate Resource Name or Location
MalwareLAMEHUG

LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareInnaputRAT

InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareLookBack

LookBack has a C2 proxy tool that masquerades as GUP.exe, which is software used by Notepad++.

T1036.005
Match Legitimate Resource Name or Location
MalwarePenquin

Penquin has mimicked the Cron binary to hide itself on compromised systems.

T1036.005
Match Legitimate Resource Name or Location
MalwareWinnti for Windows

A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name.

T1036.005
Match Legitimate Resource Name or Location
MalwareTroll Stealer

Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file.

T1036.005
Match Legitimate Resource Name or Location
MalwareChChes

ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe).

T1036.005
Match Legitimate Resource Name or Location
MalwareANDROMEDA

ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service.

T1036.005
Match Legitimate Resource Name or Location
MalwareIceApple

IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareShai-Hulud

Shai-Hulud has masqueraded as a legitimate Bun installer.

T1036.005
Match Legitimate Resource Name or Location
MalwareVIRTUALPITA

VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareKOCTOPUS

KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries.

T1036.005
Match Legitimate Resource Name or Location
MalwareMechaFlounder

MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file.

T1036.005
Match Legitimate Resource Name or Location
MalwareHTTPBrowser

HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL.

T1036.005
Match Legitimate Resource Name or Location
MalwareMis-Type

Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareOctopus

Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger.

T1036.005
Match Legitimate Resource Name or Location
MalwareQilin

Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.

T1036.005
Match Legitimate Resource Name or Location
MalwareBADNEWS

BADNEWS attempts to hide its payloads using legitimate filenames.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoopy

Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.