Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
CampaignRedPenguin | During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Sharpshooter | During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0018 | For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignHomeLand Justice | During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0032 | During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files. |
| T1036.005 Match Legitimate Resource Name or Location |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Wocao | During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0017 | During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.