Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupSandworm Team | Sandworm Team has avoided detection by naming a malicious binary explorer.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMachete | Machete's Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSidewinder | Sidewinder has named malicious files |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustang Panda | Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRocke | Rocke has used shell scripts which download mining executables and saves them with the filename "java". |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT39 | APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTA2541 | TA2541 has used file names to mimic legitimate Windows files or system functionality. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAkira | Akira has used legitimate names and locations for files to evade defenses. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupOilRig | OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupCarbanak | Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTropic Trooper | Tropic Trooper has hidden payloads in Flash directories and fake installer files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAquatic Panda | Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFerocious Kitten | Ferocious Kitten has named malicious files |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKe3chang | Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT1 | The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBlue Mockingbird | Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTurla | Turla has named components of LunarWeb to mimic Zabbix agent logs. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPoseidon Group | Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRedCurl | RedCurl mimicked legitimate file names and scheduled tasks, e.g. ` MicrosoftCurrentupdatesCheck` and |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT29 | APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupChimera | Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBRONZE BUTLER | BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBackdoorDiplomacy | BackdoorDiplomacy has dropped implants in folders named for legitimate software. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupDarkhotel | Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEmber Bear | Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupToddyCat | ToddyCat has used the name `debug.exe` for malware components. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWhitefly | Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLuminousMoth | LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT28 | APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT42 | APT42 has masqueraded the VINETHORN payload as a VPN application. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT5 | APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFox Kitten | Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT-C-36 | APT-C-36 has disguised malicious executables to appear as legitimate files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLazarus Group | Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupINC Ransom | INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEarth Lusca | Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSilence | Silence has named its backdoor "WINWORD.exe". |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSowbug | Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVelvet Ant | Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTransparent Tribe | Transparent Tribe can mimic legitimate Windows directories by using the same icons and names. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVOID MANTICORE | VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPROMETHIUM | PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWIRTE | WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMagic Hound | Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN13 | FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareEKANS | EKANS has been disguised as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBLINDINGCAN | BLINDINGCAN has attempted to hide its payload by using legitimate file names such as "iconcache.db". |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNinja | Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBumblebee | Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBRICKSTORM | BRICKSTORM has appeared to resemble legitimate processes to include the vCenter process `vami-http`. BRICKSTORM has also leveraged legitimate names of VMware vSphere platform such as `vmsrc` or `vmware-sphere`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.