Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036 Masquerading |
MalwareXCSSET | XCSSET installs malicious application bundles that mimic native macOS apps, such as Safari, by using the legitimate app’s icon and customizing the `Info.plist` to match expected metadata. |
| T1036.001 Invalid Code Signature |
GroupAPT37 | APT37 has signed its malware with an invalid digital certificates listed as “Tencent Technology (Shenzhen) Company Limited.” |
| T1036.001 Invalid Code Signature |
GroupWindshift | Windshift has used revoked certificates to sign malware. |
| T1036.001 Invalid Code Signature |
MalwareWindTail | WindTail has been incompletely signed with revoked certificates. |
| T1036.001 Invalid Code Signature |
MalwareNETWIRE | The NETWIRE client has been signed by fake and invalid digital certificates. |
| T1036.001 Invalid Code Signature |
MalwareRegin | Regin stage 1 modules for 64-bit systems have been found to be signed with fake certificates masquerading as originating from Microsoft Corporation and Broadcom Corporation. |
| T1036.001 Invalid Code Signature |
MalwareBADNEWS | BADNEWS is sometimes signed with an invalid Authenticode certificate in an apparent effort to make it look more legitimate. |
| T1036.001 Invalid Code Signature |
MalwareGelsemium | Gelsemium has used unverified signatures on malicious DLLs. |
| T1036.001 Invalid Code Signature |
MalwareSplatCloak | SplatCloak has used a revoked certificate to exploit Windows driver execution policy where certificates issued before a specific date could still load. |
| T1036.001 Invalid Code Signature |
ToolPcShare | PcShare has used an invalid certificate in attempt to appear legitimate. |
| T1036.002 Right-to-Left Override |
GroupFerocious Kitten | Ferocious Kitten has used right-to-left override to reverse executables’ names to make them appear to have different file extensions, rather than their real ones. |
| T1036.002 Right-to-Left Override |
GroupKe3chang | Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files. |
| T1036.002 Right-to-Left Override |
GroupBlackTech | BlackTech has used right-to-left-override to obfuscate the filenames of malicious e-mail attachments. |
| T1036.002 Right-to-Left Override |
GroupBRONZE BUTLER | BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware. |
| T1036.002 Right-to-Left Override |
GroupScarlet Mimic | Scarlet Mimic has used the left-to-right override character in self-extracting RAR archive spearphishing attachment file names. |
| T1036.003 Rename Legitimate Utilities |
GroupAPT38 | APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection. |
| T1036.003 Rename Legitimate Utilities |
GroupGALLIUM | GALLIUM used a renamed cmd.exe file to evade detection. |
| T1036.003 Rename Legitimate Utilities |
GroupmenuPass | menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool. |
| T1036.003 Rename Legitimate Utilities |
GroupAPT32 | APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection. |
| T1036.003 Rename Legitimate Utilities |
GroupLazarus Group | Lazarus Group has renamed system utilities such as |
| T1036.003 Rename Legitimate Utilities |
GroupDaggerfly | Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution. |
| T1036.003 Rename Legitimate Utilities |
MalwareDarkGate | DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the |
| T1036.003 Rename Legitimate Utilities |
MalwareStrelaStealer | StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation. |
| T1036.003 Rename Legitimate Utilities |
MalwarePHASEJAM | PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script. |
| T1036.003 Rename Legitimate Utilities |
MalwareCozyCar | The CozyCar dropper has masqueraded a copy of the infected system's rundll32.exe executable that was moved to the malware's install directory and renamed according to a predefined configuration file. |
| T1036.003 Rename Legitimate Utilities |
MalwareKevin | Kevin has renamed an image of `cmd.exe` with a random name followed by a `.tmpl` extension. |
| T1036.004 Masquerade Task or Service |
CampaignKV Botnet Activity | KV Botnet Activity installation steps include first identifying, then stopping, any process containing |
| T1036.004 Masquerade Task or Service |
CampaignFrankenstein | During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence. |
| T1036.004 Masquerade Task or Service |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda masqueraded Registry run keys as legitimate-looking service names such as `OneNote Update` during RedDelta Modified PlugX Infection Chain Operations. |
| T1036.004 Masquerade Task or Service |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate. |
| T1036.004 Masquerade Task or Service |
CampaignAPT41 DUST | APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1036.004 Masquerade Task or Service |
CampaignC0017 | During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code. |
| T1036.004 Masquerade Task or Service |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Systemd service units to masquerade GOGETTER malware as legitimate or seemingly legitimate services. |
| T1036.004 Masquerade Task or Service |
GroupKimsuky | Kimsuky has disguised services to appear as benign software or related to operating system functions. |
| T1036.004 Masquerade Task or Service |
GroupAPT41 | APT41 has created services to appear as benign system tools. |
| T1036.004 Masquerade Task or Service |
GroupAPT32 | APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe". |
| T1036.004 Masquerade Task or Service |
GroupNaikon | Naikon renamed a malicious service |
| T1036.004 Masquerade Task or Service |
GroupFIN6 | FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service. |
| T1036.004 Masquerade Task or Service |
GroupFIN7 | FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence. |
| T1036.004 Masquerade Task or Service |
GroupZIRCONIUM | ZIRCONIUM has created a run key named |
| T1036.004 Masquerade Task or Service |
GroupUNC3886 | UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall. |
| T1036.004 Masquerade Task or Service |
GroupHigaisa | Higaisa named a shellcode loader binary |
| T1036.004 Masquerade Task or Service |
GroupCarbanak | Carbanak has copied legitimate service names to use for malicious services. |
| T1036.004 Masquerade Task or Service |
GroupAquatic Panda | Aquatic Panda created new, malicious services using names such as |
| T1036.004 Masquerade Task or Service |
GroupWinter Vivern | Winter Vivern has distributed malicious scripts and executables mimicking virus scanners. |
| T1036.004 Masquerade Task or Service |
GroupStorm-0501 | Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe. |
| T1036.004 Masquerade Task or Service |
GroupBITTER | BITTER has disguised malware as a Windows Security update service. |
| T1036.004 Masquerade Task or Service |
GroupBackdoorDiplomacy | BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations. |
| T1036.004 Masquerade Task or Service |
GroupFox Kitten | Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate. |
| T1036.004 Masquerade Task or Service |
GroupAPT-C-36 | APT-C-36 has disguised its scheduled tasks as those used by Google. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.