Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
MalwareSysUpdate | SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign. |
| T1036.004 Masquerade Task or Service |
MalwareKwampirs | Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service. |
| T1036.004 Masquerade Task or Service |
MalwareDEADEYE | DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1036.004 Masquerade Task or Service |
MalwareInnaputRAT | InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService. |
| T1036.004 Masquerade Task or Service |
MalwareEgregor | Egregor has masqueraded the svchost.exe process to exfiltrate data. |
| T1036.004 Masquerade Task or Service |
Malwarebuild_downer | build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate. |
| T1036.004 Masquerade Task or Service |
MalwareMeteor | Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool. |
| T1036.004 Masquerade Task or Service |
MalwareMaze | Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware. |
| T1036.004 Masquerade Task or Service |
MalwareComRAT | ComRAT has used a task name associated with Windows SQM Consolidator. |
| T1036.004 Masquerade Task or Service |
MalwareVIRTUALPITA | VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services. |
| T1036.004 Masquerade Task or Service |
MalwareHeyoka Backdoor | Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service. |
| T1036.004 Masquerade Task or Service |
MalwareKillDisk | KillDisk registers as a service under the Plug-And-Play Support name. |
| T1036.004 Masquerade Task or Service |
MalwareQilin | Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer. |
| T1036.004 Masquerade Task or Service |
MalwarePOWERSTATS | POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence. |
| T1036.004 Masquerade Task or Service |
MalwareDEADWOOD | DEADWOOD will attempt to masquerade its service execution using benign-looking names such as |
| T1036.004 Masquerade Task or Service |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose. |
| T1036.004 Masquerade Task or Service |
ToolCSPY Downloader | CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications. |
| T1036.004 Masquerade Task or Service |
ToolIronNetInjector | IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc. |
| T1036.004 Masquerade Task or Service |
MalwareCanisterWorm | CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignRedPenguin | During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Sharpshooter | During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0018 | For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignHomeLand Justice | During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0032 | During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files. |
| T1036.005 Match Legitimate Resource Name or Location |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Wocao | During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0017 | During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupIndrik Spider | Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSideCopy | SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustard Tempest | Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKimsuky | Kimsuky has renamed malware to legitimate names such as |
| T1036.005 Match Legitimate Resource Name or Location |
Groupadmin@338 | admin@338 actors used the following command to rename one of their tools to a benign file name: |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVolt Typhoon | Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPatchwork | Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT41 | APT41 attempted to masquerade their files as popular anti-virus software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupmenuPass | menuPass has been seen changing malicious files to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT32 | APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMuddyWater | MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupNaikon | Naikon has disguised malicious programs as Google Chrome, Adobe, and VMware executables. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupGamaredon Group | Gamaredon Group has used legitimate process names to hide malware including |
| T1036.005 Match Legitimate Resource Name or Location |
GroupStorm-1811 | Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamTNT | TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN7 | FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.