ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.004×

23 examples

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
GroupKimsuky

Kimsuky has disguised services to appear as benign software or related to operating system functions.

T1036.004
Masquerade Task or Service
GroupAPT41

APT41 has created services to appear as benign system tools.

T1036.004
Masquerade Task or Service
GroupAPT32

APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe".

T1036.004
Masquerade Task or Service
GroupNaikon

Naikon renamed a malicious service taskmgr to appear to be a legitimate version of Task Manager.

T1036.004
Masquerade Task or Service
GroupFIN6

FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service.

T1036.004
Masquerade Task or Service
GroupFIN7

FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence.

T1036.004
Masquerade Task or Service
GroupZIRCONIUM

ZIRCONIUM has created a run key named Dropbox Update Setup to mask a persistence mechanism for a malicious binary.

T1036.004
Masquerade Task or Service
GroupUNC3886

UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall.

T1036.004
Masquerade Task or Service
GroupHigaisa

Higaisa named a shellcode loader binary svchast.exe to spoof the legitimate svchost.exe.

T1036.004
Masquerade Task or Service
GroupCarbanak

Carbanak has copied legitimate service names to use for malicious services.

T1036.004
Masquerade Task or Service
GroupAquatic Panda

Aquatic Panda created new, malicious services using names such as Windows User Service to attempt to blend in with legitimate items on victim systems.

T1036.004
Masquerade Task or Service
GroupWinter Vivern

Winter Vivern has distributed malicious scripts and executables mimicking virus scanners.

T1036.004
Masquerade Task or Service
GroupStorm-0501

Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe.

T1036.004
Masquerade Task or Service
GroupBITTER

BITTER has disguised malware as a Windows Security update service.

T1036.004
Masquerade Task or Service
GroupBackdoorDiplomacy

BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations.

T1036.004
Masquerade Task or Service
GroupFox Kitten

Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate.

T1036.004
Masquerade Task or Service
GroupAPT-C-36

APT-C-36 has disguised its scheduled tasks as those used by Google.

T1036.004
Masquerade Task or Service
GroupLazarus Group

Lazarus Group has used a scheduled task named `SRCheck` to mask the execution of a malicious .dll.

T1036.004
Masquerade Task or Service
GroupWizard Spider

Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries.

T1036.004
Masquerade Task or Service
GroupVOID MANTICORE

VOID MANTICORE has masqueraded as commonly used programs and services on Windows hosts.

T1036.004
Masquerade Task or Service
GroupPROMETHIUM

PROMETHIUM has named services to appear legitimate.

T1036.004
Masquerade Task or Service
GroupMagic Hound

Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task.

T1036.004
Masquerade Task or Service
GroupFIN13

FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.