Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUNSPOT | SUNSPOT was identified on disk with a filename of |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOutSteel | OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBackConfig | BackConfig has hidden malicious payloads in |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePowGoop | PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLAMEHUG | LAMEHUG payloads have been disguised with legitimate looking filenames including AI_generator_uncensored_Canvas_PRO_v0.9.exe and AI_image_generator_v0.95.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInnaputRAT | InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLookBack | LookBack has a C2 proxy tool that masquerades as |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePenquin | Penquin has mimicked the Cron binary to hide itself on compromised systems. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareWinnti for Windows | A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTroll Stealer | Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareChChes | ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe). |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareANDROMEDA | ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareIceApple | IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShai-Hulud | Shai-Hulud has masqueraded as a legitimate Bun installer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareVIRTUALPITA | VIRTUALPITA samples have been found in `/usr/libexec/setconf/ksmd` and `/usr/bin/ksmd`, named to spoof the legitimate Kernel Same-Page Merging Daemon binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKOCTOPUS | KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMechaFlounder | MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHTTPBrowser | HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMis-Type | Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOctopus | Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareQilin | Qilin has named its payload file TeamViewer_Host_Setup to disguise itself as a legitimate TeamViewer file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBADNEWS | BADNEWS attempts to hide its payloads using legitimate filenames. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGoopy | Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGelsemium | Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareOSX/Shlayer | OSX/Shlayer can masquerade as a Flash Player update. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDtrack | One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrifeWater | StrifeWater has been named `calc.exe` to appear as a legitimate calculator program. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareXORIndex Loader | XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSmall Sieve | Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHermeticWizard | HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolShimRatReporter | ShimRatReporter spoofed itself as |
| T1036.005 Match Legitimate Resource Name or Location |
ToolPcShare | PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolBrute Ratel C4 | Brute Ratel C4 has used a payload file named OneDrive.update to appear benign. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolMCMD | MCMD has been named Readme.txt to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCanisterWorm | CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamPCP | TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupShinyHunters | ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe. |
| T1036.006 Space after Filename |
GroupAPT38 | APT38 has put several spaces before a file extension to avoid detection and suspicion. |
| T1036.006 Space after Filename |
MalwareKeydnap | Keydnap puts a space after a false .jpg extension so that execution actually goes through the Terminal.app program. |
| T1036.007 Double File Extension |
GroupKimsuky | Kimsuky has used an additional filename extension to hide the true file type. Kimsuky has also masqueraded malicious LNK files as PDF objects using the double extension .pdf.lnk. |
| T1036.007 Double File Extension |
GroupMustang Panda | Mustang Panda has used an additional filename extension to hide the true file type. |
| T1036.007 Double File Extension |
MalwareDarkGate | DarkGate masquerades malicious LNK files as PDF objects using the double extension |
| T1036.007 Double File Extension |
MalwareBazar | The Bazar loader has used dual-extension executable files such as PreviewReport.DOC.exe. |
| T1036.007 Double File Extension |
MalwareMilan | Milan has used an executable named `companycatalog.exe.config` to appear benign. |
| T1036.008 Masquerade File Type |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection. |
| T1036.008 Masquerade File Type |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files. |
| T1036.008 Masquerade File Type |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as `.txt` files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.