Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
GroupKimsuky | Kimsuky has disguised services to appear as benign software or related to operating system functions. |
| T1036.004 Masquerade Task or Service |
GroupAPT41 | APT41 has created services to appear as benign system tools. |
| T1036.004 Masquerade Task or Service |
GroupAPT32 | APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe". |
| T1036.004 Masquerade Task or Service |
GroupNaikon | Naikon renamed a malicious service |
| T1036.004 Masquerade Task or Service |
GroupFIN6 | FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service. |
| T1036.004 Masquerade Task or Service |
GroupFIN7 | FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence. |
| T1036.004 Masquerade Task or Service |
GroupZIRCONIUM | ZIRCONIUM has created a run key named |
| T1036.004 Masquerade Task or Service |
GroupUNC3886 | UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall. |
| T1036.004 Masquerade Task or Service |
GroupHigaisa | Higaisa named a shellcode loader binary |
| T1036.004 Masquerade Task or Service |
GroupCarbanak | Carbanak has copied legitimate service names to use for malicious services. |
| T1036.004 Masquerade Task or Service |
GroupAquatic Panda | Aquatic Panda created new, malicious services using names such as |
| T1036.004 Masquerade Task or Service |
GroupWinter Vivern | Winter Vivern has distributed malicious scripts and executables mimicking virus scanners. |
| T1036.004 Masquerade Task or Service |
GroupStorm-0501 | Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe. |
| T1036.004 Masquerade Task or Service |
GroupBITTER | BITTER has disguised malware as a Windows Security update service. |
| T1036.004 Masquerade Task or Service |
GroupBackdoorDiplomacy | BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations. |
| T1036.004 Masquerade Task or Service |
GroupFox Kitten | Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate. |
| T1036.004 Masquerade Task or Service |
GroupAPT-C-36 | APT-C-36 has disguised its scheduled tasks as those used by Google. |
| T1036.004 Masquerade Task or Service |
GroupLazarus Group | Lazarus Group has used a scheduled task named `SRCheck` to mask the execution of a malicious .dll. |
| T1036.004 Masquerade Task or Service |
GroupWizard Spider | Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries. |
| T1036.004 Masquerade Task or Service |
GroupVOID MANTICORE | VOID MANTICORE has masqueraded as commonly used programs and services on Windows hosts. |
| T1036.004 Masquerade Task or Service |
GroupPROMETHIUM | PROMETHIUM has named services to appear legitimate. |
| T1036.004 Masquerade Task or Service |
GroupMagic Hound | Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task. |
| T1036.004 Masquerade Task or Service |
GroupFIN13 | FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.