Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGelsemium | Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOSX/Shlayer | OSX/Shlayer can masquerade as a Flash Player update. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDtrack | One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrifeWater | StrifeWater has been named `calc.exe` to appear as a legitimate calculator program. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareXORIndex Loader | XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSmall Sieve | Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHermeticWizard | HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolShimRatReporter | ShimRatReporter spoofed itself as |
| T1036.005 Match Legitimate Resource Name or Location |
ToolPcShare | PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolBrute Ratel C4 | Brute Ratel C4 has used a payload file named OneDrive.update to appear benign. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolMCMD | MCMD has been named Readme.txt to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCanisterWorm | CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files. |
| T1036.006 Space after Filename |
MalwareKeydnap | Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program. |
| T1036.007 Double File Extension |
MalwareDarkGate | DarkGate masquerades malicious LNK files as PDF objects using the double extension |
| T1036.007 Double File Extension |
MalwareBazar | The Bazar loader has used dual-extension executable files such as PreviewReport.DOC.exe. |
| T1036.007 Double File Extension |
MalwareMilan | Milan has used an executable named `companycatalog.exe.config` to appear benign. |
| T1036.008 Masquerade File Type |
MalwareAvosLocker | AvosLocker has been disguised as a .jpg file. |
| T1036.008 Masquerade File Type |
MalwareHeartCrypt | HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files. |
| T1036.008 Masquerade File Type |
MalwareSTATICPLUGIN | STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension. |
| T1036.008 Masquerade File Type |
MalwareRaspberry Robin | Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder. |
| T1036.008 Masquerade File Type |
MalwareLumma Stealer | Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content. |
| T1036.008 Masquerade File Type |
MalwarePureCrypter | PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files. |
| T1036.008 Masquerade File Type |
MalwareMagicRAT | MagicRAT can download additional executable payloads that masquerade as GIF files. |
| T1036.008 Masquerade File Type |
MalwareStrelaStealer | StrelaStealer has been distributed as a DLL/HTML polyglot file. |
| T1036.008 Masquerade File Type |
MalwareKapeka | Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file. |
| T1036.008 Masquerade File Type |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents. |
| T1036.008 Masquerade File Type |
MalwareANDROMEDA | ANDROMEDA has been delivered through a LNK file disguised as a folder. |
| T1036.008 Masquerade File Type |
MalwareQakBot | The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon. |
| T1036.008 Masquerade File Type |
ToolBrute Ratel C4 | Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files. |
| T1036.009 Break Process Trees |
MalwareBPFDoor | After initial execution, BPFDoor forks itself and runs the fork with the `--init` flag, which allows it to execute secondary clean up operations. The parent process terminates leaving the forked process to be inherited by the legitimate process init. |
| T1036.009 Break Process Trees |
MalwareShai-Hulud | Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally. |
| T1036.010 Masquerade Account Name |
MalwareServHelper | ServHelper has created a new user named `supportaccount`. |
| T1036.010 Masquerade Account Name |
MalwareFlame | Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available. |
| T1036.011 Overwrite Process Arguments |
MalwareBPFDoor | BPFDoor overwrites the `argv[0]` value used by the Linux `/proc` filesystem to determine the command line and command name to display for each process. BPFDoor selects a name from 10 hardcoded names that resemble Linux system daemons, such as; `/sbin/udevd -d`, `dbus-daemon --system`, `avahi-daemon: chroot helper`, `/sbin/auditd -n`, and `/usr/lib/systemd/systemd-journald`. |
| T1036.012 Browser Fingerprint |
MalwareFatDuke | FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser. |
| T1037 Boot or Logon Initialization Scripts |
MalwareRotaJakiro | Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder. |
| T1037 Boot or Logon Initialization Scripts |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence. |
| T1037 Boot or Logon Initialization Scripts |
MalwareVIRTUALPITA | VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems. |
| T1037.001 Logon Script (Windows) |
MalwareJHUHUGIT | JHUHUGIT has registered a Windows shell script under the Registry key |
| T1037.001 Logon Script (Windows) |
MalwareKGH_SPY | KGH_SPY has the ability to set the |
| T1037.001 Logon Script (Windows) |
MalwareAttor | Attor's dispatcher can establish persistence via adding a Registry key with a logon script |
| T1037.001 Logon Script (Windows) |
MalwareZebrocy | Zebrocy performs persistence with a logon script via adding to the Registry key |
| T1037.004 RC Scripts |
MalwareiKitten | iKitten adds an entry to the rc.common file for persistence. |
| T1037.004 RC Scripts |
MalwareGreen Lambert | Green Lambert can add |
| T1037.004 RC Scripts |
MalwareCyclops Blink | Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled. |
| T1037.004 RC Scripts |
MalwareHiddenWasp | HiddenWasp installs reboot persistence by adding itself to |
| T1037.005 Startup Items |
MalwarejRAT | jRAT can list and manage startup entries. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.