Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrelaStealer | StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGrandoreiro | Grandoreiro has named malicious browser extensions and update files to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStarloader | Starloader has masqueraded as legitimate software update packages such as Adobe Acrobat Reader and Intel. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSibot | Sibot has downloaded a DLL to the |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTarrask | Tarrask has masqueraded as executable files such as `winupdate.exe`, `date.exe`, or `win.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoBear | GoBear is installed through droppers masquerading as legitimate, signed software installers. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShark | Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBazar | The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUGARDUMP | SUGARDUMP has been named `CrashReporter.exe` to appear as a legitimate Mozilla executable. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRyuk | Ryuk has constructed legitimate appearing installation folder paths by calling |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHermeticWiper | HermeticWiper has used the name `postgressql.exe` to mask a malicious payload. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePysa | Pysa has executed a malicious executable by naming it svchost.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFinFisher | FinFisher renames one of its .dll files to uxtheme.dll in an apparent attempt to masquerade as a legitimate file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOwaAuth | OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUNBURST | SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareREvil | REvil can mimic the names of known executables. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSamurai | Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareUSBStealer | USBStealer mimics a legitimate Russian program called USB Disk Security. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUPERNOVA | SUPERNOVA has masqueraded as a legitimate SolarWinds DLL. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCyclops Blink | Cyclops Blink can rename its running process to |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDaserf | Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDanBot | DanBot files have been named `UltraVNC.exe` and `WINVNC.exe` to appear as legitimate VNC tools. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCalisto | Calisto's installation file is an unsigned DMG image under the guise of Intego’s security solution for mac. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoldenSpy | GoldenSpy's setup file installs initial executables under the folder |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRamsay | Ramsay has masqueraded as a 7zip installer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareAshTag | AshTag has masqueraded as a legitimate VisualServer utility. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCarberp | Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe". |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUNSPOT | SUNSPOT was identified on disk with a filename of |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOutSteel | OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBackConfig | BackConfig has hidden malicious payloads in |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePowGoop | PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLAMEHUG | LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInnaputRAT | InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLookBack | LookBack has a C2 proxy tool that masquerades as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePenquin | Penquin has mimicked the Cron binary to hide itself on compromised systems. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareWinnti for Windows | A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTroll Stealer | Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChChes | ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe). |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareANDROMEDA | ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIceApple | IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShai-Hulud | Shai-Hulud has masqueraded as a legitimate Bun installer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareVIRTUALPITA | VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKOCTOPUS | KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMechaFlounder | MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHTTPBrowser | HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMis-Type | Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOctopus | Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQilin | Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBADNEWS | BADNEWS attempts to hide its payloads using legitimate filenames. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoopy | Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.