ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.004×

63 examples

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
MalwareExaramel for Windows

The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV” in an apparent attempt to masquerade as a legitimate service.

T1036.004
Masquerade Task or Service
MalwareStrongPity

StrongPity has named services to appear legitimate.

T1036.004
Masquerade Task or Service
MalwareNebulae

Nebulae has created a service named "Windows Update Agent1" to appear legitimate.

T1036.004
Masquerade Task or Service
MalwareTONESHELL

TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service).

T1036.004
Masquerade Task or Service
MalwareRainyDay

RainyDay has named services and scheduled tasks to appear benign including "ChromeCheck" and "googleupdate."

T1036.004
Masquerade Task or Service
MalwareTinyTurla

TinyTurla has mimicked an existing Windows service by being installed as Windows Time Service.

T1036.004
Masquerade Task or Service
MalwareBOOKWORM

BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`.

T1036.004
Masquerade Task or Service
MalwareEmotet

Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`.

T1036.004
Masquerade Task or Service
MalwareTurian

Turian can disguise as a legitimate service to blend into normal operations.

T1036.004
Masquerade Task or Service
MalwareMachete

Machete renamed task names to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python tasks.

T1036.004
Masquerade Task or Service
MalwarePingPull

PingPull can mimic the names and descriptions of legitimate services such as `iphlpsvc`, `IP Helper`, and `Onedrive` to evade detection.

T1036.004
Masquerade Task or Service
MalwareHildegard

Hildegard has disguised itself as a known Linux process.

T1036.004
Masquerade Task or Service
MalwareInvisiMole

InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name.

T1036.004
Masquerade Task or Service
MalwareVolgmer

Some Volgmer variants add new services with display names generated by a list of hard-coded strings such as Application, Background, Security, and Windows, presumably as a way to masquerade as a legitimate service.

T1036.004
Masquerade Task or Service
MalwareRDAT

RDAT has used Windows Video Service as a name for malicious services.

T1036.004
Masquerade Task or Service
MalwareOkrum

Okrum can establish persistence by adding a new service NtmsSvc with the display name Removable Storage to masquerade as a legitimate Removable Storage Manager.

T1036.004
Masquerade Task or Service
MalwareRaspberry Robin

Raspberry Robin will execute its payload prior to initializing command and control traffic by impersonating one of several legitimate program names such as dllhost.exe, regsvr32.exe, or rundll32.exe.

T1036.004
Masquerade Task or Service
MalwareFysbis

Fysbis has masqueraded as the rsyncd and dbus-inotifier services.

T1036.004
Masquerade Task or Service
MalwareDCSrv

DCSrv has masqueraded its service as a legitimate svchost.exe process.

T1036.004
Masquerade Task or Service
MalwareShimRat

ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems.

T1036.004
Masquerade Task or Service
MalwareGreen Lambert

Green Lambert has created a new executable named `Software Update Check` to appear legitimate.

T1036.004
Masquerade Task or Service
MalwareGoldMax

GoldMax has impersonated systems management software to avoid detection.

T1036.004
Masquerade Task or Service
MalwarePlugX

In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility."

T1036.004
Masquerade Task or Service
MalwareTruvasys

To establish persistence, Truvasys adds a Registry Run key with a value "TaskMgr" in an attempt to masquerade as the legitimate Windows Task Manager.

T1036.004
Masquerade Task or Service
MalwareSVCReady

SVCReady has named a task `RecoveryExTask` as part of its persistence activity.

T1036.004
Masquerade Task or Service
MalwareUroburos

Uroburos has registered a service named `WerFaultSvc`, likely to spoof the legitimate Windows error reporting service.

T1036.004
Masquerade Task or Service
MalwareSpica

Spica has created a scheduled task named `CalendarChecker` for persistence on compromised hosts.

T1036.004
Masquerade Task or Service
MalwareKONNI

KONNI has pretended to be the xmlProv Network Provisioning service.

T1036.004
Masquerade Task or Service
MalwareShamoon

Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance."

T1036.004
Masquerade Task or Service
MalwareBlack Basta

Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name.

T1036.004
Masquerade Task or Service
MalwareCatchamas

Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service.

T1036.004
Masquerade Task or Service
MalwareAttor

Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate).

T1036.004
Masquerade Task or Service
MalwareNightClub

NightClub has created a service named `WmdmPmSp` to spoof a Windows Media service.

T1036.004
Masquerade Task or Service
MalwareCrutch

Crutch has established persistence with a scheduled task impersonating the Outlook item finder.

T1036.004
Masquerade Task or Service
MalwareRTM

RTM has named the scheduled task it creates "Windows Update".

T1036.004
Masquerade Task or Service
MalwareRawPOS

New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager".

T1036.004
Masquerade Task or Service
MalwareZxxZ

ZxxZ has been disguised as a Windows security update service.

T1036.004
Masquerade Task or Service
MalwareTarrask

Tarrask creates a scheduled task called “WinUpdate” to re-establish any dropped C2 connections.

T1036.004
Masquerade Task or Service
MalwareBazar

Bazar can create a task named to appear benign.

T1036.004
Masquerade Task or Service
MalwareSUGARDUMP

SUGARDUMP's scheduled task has been named `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` or `MicrosoftEdgeCrashRepoeterTaskMachineUA`, depending on the Windows OS version.

T1036.004
Masquerade Task or Service
MalwareNidiran

Nidiran can create a new service named msamger (Microsoft Security Accounts Manager), which mimics the legitimate Microsoft database by the same name.

T1036.004
Masquerade Task or Service
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses file naming conventions with associated executable locations to blend in with the macOS TimeMachine and OpenSSL services. Such as, naming a LaunchAgent plist file `com.apple.openssl.plist` which executes OSX_OCEANLOTUS.D from the user's `~/Library/OpenSSL/` folder upon user login.

T1036.004
Masquerade Task or Service
MalwareSeasalt

Seasalt has masqueraded as a service called "SaSaut" with a display name of "System Authorization Service" in an apparent attempt to masquerade as a legitimate service.

T1036.004
Masquerade Task or Service
MalwareFunnyDream

FunnyDream has used a service named `WSearch` for execution.

T1036.004
Masquerade Task or Service
MalwareSysUpdate

SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign.

T1036.004
Masquerade Task or Service
MalwareKwampirs

Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service.

T1036.004
Masquerade Task or Service
MalwareDEADEYE

DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1036.004
Masquerade Task or Service
MalwareInnaputRAT

InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService.

T1036.004
Masquerade Task or Service
MalwareEgregor

Egregor has masqueraded the svchost.exe process to exfiltrate data.

T1036.004
Masquerade Task or Service
Malwarebuild_downer

build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.