ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.005×

15 examples

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
CampaignRedPenguin

During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC.

T1036.005
Match Legitimate Resource Name or Location
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0018

For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`.

T1036.005
Match Legitimate Resource Name or Location
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization.

T1036.005
Match Legitimate Resource Name or Location
CampaignHomeLand Justice

During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0032

During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.

T1036.005
Match Legitimate Resource Name or Location
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files.

T1036.005
Match Legitimate Resource Name or Location
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Wocao

During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0017

During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.