ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
MalwareSysUpdate

SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign.

T1036.004
Masquerade Task or Service
MalwareKwampirs

Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service.

T1036.004
Masquerade Task or Service
MalwareDEADEYE

DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1036.004
Masquerade Task or Service
MalwareInnaputRAT

InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService.

T1036.004
Masquerade Task or Service
MalwareEgregor

Egregor has masqueraded the svchost.exe process to exfiltrate data.

T1036.004
Masquerade Task or Service
Malwarebuild_downer

build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate.

T1036.004
Masquerade Task or Service
MalwareMeteor

Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool.

T1036.004
Masquerade Task or Service
MalwareMaze

Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware.

T1036.004
Masquerade Task or Service
MalwareComRAT

ComRAT has used a task name associated with Windows SQM Consolidator.

T1036.004
Masquerade Task or Service
MalwareVIRTUALPITA

VIRTUALPITA has utilized VMware service names and ports to masquerade as legitimate services.

T1036.004
Masquerade Task or Service
MalwareHeyoka Backdoor

Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service.

T1036.004
Masquerade Task or Service
MalwareKillDisk

KillDisk registers as a service under the Plug-And-Play Support name.

T1036.004
Masquerade Task or Service
MalwareQilin

Qilin has created a scheduled task named TVInstallRestore to mimic TeamViewer.

T1036.004
Masquerade Task or Service
MalwarePOWERSTATS

POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence.

T1036.004
Masquerade Task or Service
MalwareDEADWOOD

DEADWOOD will attempt to masquerade its service execution using benign-looking names such as ScDeviceEnums.

T1036.004
Masquerade Task or Service
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose.

T1036.004
Masquerade Task or Service
ToolCSPY Downloader

CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications.

T1036.004
Masquerade Task or Service
ToolIronNetInjector

IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc.

T1036.004
Masquerade Task or Service
MalwareCanisterWorm

CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon.

T1036.005
Match Legitimate Resource Name or Location
CampaignRedPenguin

During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC.

T1036.005
Match Legitimate Resource Name or Location
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0018

For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`.

T1036.005
Match Legitimate Resource Name or Location
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization.

T1036.005
Match Legitimate Resource Name or Location
CampaignHomeLand Justice

During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0032

During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.

T1036.005
Match Legitimate Resource Name or Location
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files.

T1036.005
Match Legitimate Resource Name or Location
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Wocao

During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0017

During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections.

T1036.005
Match Legitimate Resource Name or Location
GroupIndrik Spider

Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors.

T1036.005
Match Legitimate Resource Name or Location
GroupSideCopy

SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool.

T1036.005
Match Legitimate Resource Name or Location
GroupMustard Tempest

Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`.

T1036.005
Match Legitimate Resource Name or Location
GroupKimsuky

Kimsuky has renamed malware to legitimate names such as ESTCommon.dll or patch.dll. Kimsuky has also disguised payloads using legitimate file names including a PowerShell payload named chrome.ps1. Kimsuky has also used a malicious QR code that masqueraded as a legitimate package delivery service.

T1036.005
Match Legitimate Resource Name or Location
Groupadmin@338

admin@338 actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe

T1036.005
Match Legitimate Resource Name or Location
GroupVolt Typhoon

Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.

T1036.005
Match Legitimate Resource Name or Location
GroupPatchwork

Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT41

APT41 attempted to masquerade their files as popular anti-virus software.

T1036.005
Match Legitimate Resource Name or Location
GroupmenuPass

menuPass has been seen changing malicious files to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT32

APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupMuddyWater

MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender.

T1036.005
Match Legitimate Resource Name or Location
GroupNaikon

Naikon has disguised malicious programs as Google Chrome, Adobe, and VMware executables.

T1036.005
Match Legitimate Resource Name or Location
GroupGamaredon Group

Gamaredon Group has used legitimate process names to hide malware including svchosst. Additionally, Gamaredon Group disguised malicious ZIP archives as Office documents that are related to the invasion.

T1036.005
Match Legitimate Resource Name or Location
GroupStorm-1811

Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package.

T1036.005
Match Legitimate Resource Name or Location
GroupTeamTNT

TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software.

T1036.005
Match Legitimate Resource Name or Location
GroupFIN7

FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.