ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1036
Masquerading
MalwareXCSSET

XCSSET installs malicious application bundles that mimic native macOS apps, such as Safari, by using the legitimate app’s icon and customizing the `Info.plist` to match expected metadata.

T1036.001
Invalid Code Signature
GroupAPT37

APT37 has signed its malware with an invalid digital certificates listed as “Tencent Technology (Shenzhen) Company Limited.”

T1036.001
Invalid Code Signature
GroupWindshift

Windshift has used revoked certificates to sign malware.

T1036.001
Invalid Code Signature
MalwareWindTail

WindTail has been incompletely signed with revoked certificates.

T1036.001
Invalid Code Signature
MalwareNETWIRE

The NETWIRE client has been signed by fake and invalid digital certificates.

T1036.001
Invalid Code Signature
MalwareRegin

Regin stage 1 modules for 64-bit systems have been found to be signed with fake certificates masquerading as originating from Microsoft Corporation and Broadcom Corporation.

T1036.001
Invalid Code Signature
MalwareBADNEWS

BADNEWS is sometimes signed with an invalid Authenticode certificate in an apparent effort to make it look more legitimate.

T1036.001
Invalid Code Signature
MalwareGelsemium

Gelsemium has used unverified signatures on malicious DLLs.

T1036.001
Invalid Code Signature
MalwareSplatCloak

SplatCloak has used a revoked certificate to exploit Windows driver execution policy where certificates issued before a specific date could still load.

T1036.001
Invalid Code Signature
ToolPcShare

PcShare has used an invalid certificate in attempt to appear legitimate.

T1036.002
Right-to-Left Override
GroupFerocious Kitten

Ferocious Kitten has used right-to-left override to reverse executables’ names to make them appear to have different file extensions, rather than their real ones.

T1036.002
Right-to-Left Override
GroupKe3chang

Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files.

T1036.002
Right-to-Left Override
GroupBlackTech

BlackTech has used right-to-left-override to obfuscate the filenames of malicious e-mail attachments.

T1036.002
Right-to-Left Override
GroupBRONZE BUTLER

BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware.

T1036.002
Right-to-Left Override
GroupScarlet Mimic

Scarlet Mimic has used the left-to-right override character in self-extracting RAR archive spearphishing attachment file names.

T1036.003
Rename Legitimate Utilities
GroupAPT38

APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection.

T1036.003
Rename Legitimate Utilities
GroupGALLIUM

GALLIUM used a renamed cmd.exe file to evade detection.

T1036.003
Rename Legitimate Utilities
GroupmenuPass

menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool.

T1036.003
Rename Legitimate Utilities
GroupAPT32

APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection.

T1036.003
Rename Legitimate Utilities
GroupLazarus Group

Lazarus Group has renamed system utilities such as wscript.exe and mshta.exe.

T1036.003
Rename Legitimate Utilities
GroupDaggerfly

Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution.

T1036.003
Rename Legitimate Utilities
MalwareDarkGate

DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the C:\\ root directory that copies and renames the legitimate Windows <curl>curl</code> command to this new location.

T1036.003
Rename Legitimate Utilities
MalwareStrelaStealer

StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation.

T1036.003
Rename Legitimate Utilities
MalwarePHASEJAM

PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script.

T1036.003
Rename Legitimate Utilities
MalwareCozyCar

The CozyCar dropper has masqueraded a copy of the infected system's rundll32.exe executable that was moved to the malware's install directory and renamed according to a predefined configuration file.

T1036.003
Rename Legitimate Utilities
MalwareKevin

Kevin has renamed an image of `cmd.exe` with a random name followed by a `.tmpl` extension.

T1036.004
Masquerade Task or Service
CampaignKV Botnet Activity

KV Botnet Activity installation steps include first identifying, then stopping, any process containing [kworker\/0:1], then renaming its initial installation stage to this process name.

T1036.004
Masquerade Task or Service
CampaignFrankenstein

During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence.

T1036.004
Masquerade Task or Service
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda masqueraded Registry run keys as legitimate-looking service names such as `OneNote Update` during RedDelta Modified PlugX Infection Chain Operations.

T1036.004
Masquerade Task or Service
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate.

T1036.004
Masquerade Task or Service
CampaignAPT41 DUST

APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1036.004
Masquerade Task or Service
CampaignC0017

During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code.

T1036.004
Masquerade Task or Service
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Systemd service units to masquerade GOGETTER malware as legitimate or seemingly legitimate services.

T1036.004
Masquerade Task or Service
GroupKimsuky

Kimsuky has disguised services to appear as benign software or related to operating system functions.

T1036.004
Masquerade Task or Service
GroupAPT41

APT41 has created services to appear as benign system tools.

T1036.004
Masquerade Task or Service
GroupAPT32

APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe".

T1036.004
Masquerade Task or Service
GroupNaikon

Naikon renamed a malicious service taskmgr to appear to be a legitimate version of Task Manager.

T1036.004
Masquerade Task or Service
GroupFIN6

FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service.

T1036.004
Masquerade Task or Service
GroupFIN7

FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence.

T1036.004
Masquerade Task or Service
GroupZIRCONIUM

ZIRCONIUM has created a run key named Dropbox Update Setup to mask a persistence mechanism for a malicious binary.

T1036.004
Masquerade Task or Service
GroupUNC3886

UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall.

T1036.004
Masquerade Task or Service
GroupHigaisa

Higaisa named a shellcode loader binary svchast.exe to spoof the legitimate svchost.exe.

T1036.004
Masquerade Task or Service
GroupCarbanak

Carbanak has copied legitimate service names to use for malicious services.

T1036.004
Masquerade Task or Service
GroupAquatic Panda

Aquatic Panda created new, malicious services using names such as Windows User Service to attempt to blend in with legitimate items on victim systems.

T1036.004
Masquerade Task or Service
GroupWinter Vivern

Winter Vivern has distributed malicious scripts and executables mimicking virus scanners.

T1036.004
Masquerade Task or Service
GroupStorm-0501

Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe.

T1036.004
Masquerade Task or Service
GroupBITTER

BITTER has disguised malware as a Windows Security update service.

T1036.004
Masquerade Task or Service
GroupBackdoorDiplomacy

BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations.

T1036.004
Masquerade Task or Service
GroupFox Kitten

Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate.

T1036.004
Masquerade Task or Service
GroupAPT-C-36

APT-C-36 has disguised its scheduled tasks as those used by Google.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.