ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareSUNSPOT

SUNSPOT was identified on disk with a filename of taskhostsvc.exe and it created an encrypted log file at C:\Windows\Temp\vmware-vmdmp.log.

T1036.005
Match Legitimate Resource Name or Location
MalwareOutSteel

OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: %TEMP%\\svjhost.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareBackConfig

BackConfig has hidden malicious payloads in %USERPROFILE%\Adobe\Driver\dwg\ and mimicked the legitimate DHCP service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwarePowGoop

PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file.

T1036.005
Match Legitimate Resource Name or Location
MalwareLAMEHUG

LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareInnaputRAT

InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareLookBack

LookBack has a C2 proxy tool that masquerades as GUP.exe, which is software used by Notepad++.

T1036.005
Match Legitimate Resource Name or Location
MalwarePenquin

Penquin has mimicked the Cron binary to hide itself on compromised systems.

T1036.005
Match Legitimate Resource Name or Location
MalwareWinnti for Windows

A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name.

T1036.005
Match Legitimate Resource Name or Location
MalwareTroll Stealer

Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file.

T1036.005
Match Legitimate Resource Name or Location
MalwareChChes

ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe).

T1036.005
Match Legitimate Resource Name or Location
MalwareANDROMEDA

ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service.

T1036.005
Match Legitimate Resource Name or Location
MalwareIceApple

IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareShai-Hulud

Shai-Hulud has masqueraded as a legitimate Bun installer.

T1036.005
Match Legitimate Resource Name or Location
MalwareVIRTUALPITA

VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareKOCTOPUS

KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries.

T1036.005
Match Legitimate Resource Name or Location
MalwareMechaFlounder

MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file.

T1036.005
Match Legitimate Resource Name or Location
MalwareHTTPBrowser

HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL.

T1036.005
Match Legitimate Resource Name or Location
MalwareMis-Type

Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareOctopus

Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger.

T1036.005
Match Legitimate Resource Name or Location
MalwareQilin

Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file.

T1036.005
Match Legitimate Resource Name or Location
MalwareBADNEWS

BADNEWS attempts to hide its payloads using legitimate filenames.

T1036.005
Match Legitimate Resource Name or Location
MalwareGoopy

Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareGelsemium

Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value Chrome Update to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareOSX/Shlayer

OSX/Shlayer can masquerade as a Flash Player update.

T1036.005
Match Legitimate Resource Name or Location
MalwareDtrack

One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrifeWater

StrifeWater has been named `calc.exe` to appear as a legitimate calculator program.

T1036.005
Match Legitimate Resource Name or Location
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareXORIndex Loader

XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads.

T1036.005
Match Legitimate Resource Name or Location
MalwareSmall Sieve

Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWizard

HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll.

T1036.005
Match Legitimate Resource Name or Location
ToolShimRatReporter

ShimRatReporter spoofed itself as AlphaZawgyl_font.exe, a specialized Unicode font.

T1036.005
Match Legitimate Resource Name or Location
ToolPcShare

PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client.

T1036.005
Match Legitimate Resource Name or Location
ToolBrute Ratel C4

Brute Ratel C4 has used a payload file named OneDrive.update to appear benign.

T1036.005
Match Legitimate Resource Name or Location
ToolMCMD

MCMD has been named Readme.txt to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems.

T1036.005
Match Legitimate Resource Name or Location
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs.

T1036.005
Match Legitimate Resource Name or Location
MalwareCanisterWorm

CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files.

T1036.005
Match Legitimate Resource Name or Location
GroupTeamPCP

TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.

T1036.005
Match Legitimate Resource Name or Location
GroupShinyHunters

ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe.

T1036.006
Space after Filename
GroupAPT38

APT38 has put several spaces before a file extension to avoid detection and suspicion.

T1036.006
Space after Filename
MalwareKeydnap

Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program.

T1036.007
Double File Extension
GroupKimsuky

Kimsuky has used an additional filename extension to hide the true file type. Kimsuky has also masqueraded malicious LNK files as PDF objects using the double extension .pdf.lnk.

T1036.007
Double File Extension
GroupMustang Panda

Mustang Panda has used an additional filename extension to hide the true file type.

T1036.007
Double File Extension
MalwareDarkGate

DarkGate masquerades malicious LNK files as PDF objects using the double extension .pdf.lnk.

T1036.007
Double File Extension
MalwareBazar

The Bazar loader has used dual-extension executable files such as PreviewReport.DOC.exe.

T1036.007
Double File Extension
MalwareMilan

Milan has used an executable named `companycatalog.exe.config` to appear benign.

T1036.008
Masquerade File Type
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection.

T1036.008
Masquerade File Type
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files.

T1036.008
Masquerade File Type
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as `.txt` files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.