Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036 Masquerading |
GroupStorm-1811 | Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations. |
| T1036 Masquerading |
GroupTeamTNT | TeamTNT has disguised their scripts with docker-related file names. |
| T1036 Masquerading |
GroupSandworm Team | Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries. |
| T1036 Masquerading |
GroupZIRCONIUM | ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware. |
| T1036 Masquerading |
GroupContagious Interview | Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Sekoia ClickFake 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1036 Masquerading |
GroupOilRig | OilRig has used .doc file extensions to mask malicious executables. |
| T1036 Masquerading |
GroupAoqin Dragon | Aoqin Dragon has used fake icons including antivirus and external drives to disguise malicious payloads. |
| T1036 Masquerading |
GroupWinter Vivern | Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns. |
| T1036 Masquerading |
GroupBRONZE BUTLER | BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF. |
| T1036 Masquerading |
GroupTA551 | TA551 has masked malware DLLs as dat and jpg files. |
| T1036 Masquerading |
GroupEmber Bear | Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as |
| T1036 Masquerading |
GroupLazyScripter | LazyScripter has used several different security software icons to disguise executables. |
| T1036 Masquerading |
GroupWindshift | Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers. |
| T1036 Masquerading |
GroupAgrius | Agrius used the Plink tool for tunneling and connections to remote machines, renaming it |
| T1036 Masquerading |
GroupAPT28 | APT28 has renamed the WinRAR utility to avoid detection. |
| T1036 Masquerading |
GroupPLATINUM | PLATINUM has renamed rar.exe to avoid detection. |
| T1036 Masquerading |
GroupFIN13 | FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file. |
| T1036 Masquerading |
GroupNomadic Octopus | Nomadic Octopus attempted to make Octopus appear as a Telegram Messenger with a Russian interface. |
| T1036 Masquerading |
MalwareTrickBot | The TrickBot downloader has used an icon to appear as a Microsoft Word document. |
| T1036 Masquerading |
MalwareRCSession | RCSession has used a file named English.rtf to appear benign on victim hosts. |
| T1036 Masquerading |
MalwareWindTail | WindTail has used icons mimicking MS Office files to mask payloads. |
| T1036 Masquerading |
MalwarePony | Pony has used the Adobe Reader icon for the downloaded file to look more trustworthy. |
| T1036 Masquerading |
MalwareUPSTYLE | UPSTYLE has masqueraded filenames using examples such as `update.py`. |
| T1036 Masquerading |
MalwareAppleSeed | AppleSeed can disguise JavaScript files as PDFs. |
| T1036 Masquerading |
MalwareEnvyScout | EnvyScout has used folder icons for malicious files to lure victims into opening them. |
| T1036 Masquerading |
MalwareDynoWiper | DynoWiper has been named after well-known files schtask.exe, schtask2.exe, and <redacted>_update.exe. |
| T1036 Masquerading |
MalwareDacls | The Dacls Mach-O binary has been disguised as a .nib file. |
| T1036 Masquerading |
MalwareSombRAT | SombRAT can use a legitimate process name to hide itself. |
| T1036 Masquerading |
MalwareWhisperGate | WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file. |
| T1036 Masquerading |
MalwareRaindrop | Raindrop was built to include a modified version of 7-Zip source code (including associated export names) and Far Manager source code. |
| T1036 Masquerading |
MalwareNotPetya | |
| T1036 Masquerading |
MalwareFlagpro | Flagpro can download malicious files with a .tmp extension and append them with .exe prior to execution. |
| T1036 Masquerading |
MalwareDarkTortilla | DarkTortilla's payload has been renamed `PowerShellInfo.exe`. |
| T1036 Masquerading |
MalwareBeaverTail | BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes. |
| T1036 Masquerading |
MalwareDarkWatchman | DarkWatchman has used an icon mimicking a text file to mask a malicious executable. |
| T1036 Masquerading |
MalwareBisonal | Bisonal dropped a decoy payload with a .jpg extension that contained a malicious Visual Basic script. |
| T1036 Masquerading |
MalwareDarkGate | DarkGate can masquerade as pirated media content for initial delivery to victims. |
| T1036 Masquerading |
MalwareFoggyWeb | FoggyWeb can masquerade the output of C2 commands as a fake, but legitimately formatted WebP file. |
| T1036 Masquerading |
MalwareSaint Bot | Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection. |
| T1036 Masquerading |
MalwareGlassWorm | GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects. |
| T1036 Masquerading |
MalwareRedLine Stealer | RedLine Stealer malware has masqueraded as legitimate software such as "PDF Converter Software" which has been distributed through poisoned search engine results often resembling legitimate software lures with the combination of typo squatted domains. |
| T1036 Masquerading |
MalwareRTM | RTM has been delivered as archived Windows executable files masquerading as PDF documents. |
| T1036 Masquerading |
MalwareStrelaStealer | StrelaStealer PE executable payloads have used uncommon but legitimate extensions such as `.com` instead of `.exe`. |
| T1036 Masquerading |
MalwareRyuk | Ryuk can create .dll files that actually contain a Rich Text File format document. |
| T1036 Masquerading |
MalwareMilan | Milan has used an executable named `companycatalogue` to appear benign. |
| T1036 Masquerading |
MalwareNativeZone | NativeZone has, upon execution, displayed a message box that appears to be related to a Ukrainian electronic document management system. |
| T1036 Masquerading |
MalwareRamsay | Ramsay has masqueraded as a JPG image file. |
| T1036 Masquerading |
MalwareTrailBlazer | TrailBlazer has used filenames that match the name of the compromised system in attempt to avoid detection. |
| T1036 Masquerading |
MalwarePowGoop | PowGoop has disguised a PowerShell script as a .dat file (goopdate.dat). |
| T1036 Masquerading |
MalwareBoomBox | BoomBox has the ability to mask malicious data strings as PDF files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.