ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036.008×

13 examples

TechniqueUsed byProcedure example
T1036.008
Masquerade File Type
MalwareAvosLocker

AvosLocker has been disguised as a .jpg file.

T1036.008
Masquerade File Type
MalwareHeartCrypt

HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files.

T1036.008
Masquerade File Type
MalwareSTATICPLUGIN

STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension.

T1036.008
Masquerade File Type
MalwareRaspberry Robin

Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder.

T1036.008
Masquerade File Type
MalwareLumma Stealer

Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content.

T1036.008
Masquerade File Type
MalwarePureCrypter

PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files.

T1036.008
Masquerade File Type
MalwareMagicRAT

MagicRAT can download additional executable payloads that masquerade as GIF files.

T1036.008
Masquerade File Type
MalwareStrelaStealer

StrelaStealer has been distributed as a DLL/HTML polyglot file.

T1036.008
Masquerade File Type
MalwareKapeka

Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file.

T1036.008
Masquerade File Type
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents.

T1036.008
Masquerade File Type
MalwareANDROMEDA

ANDROMEDA has been delivered through a LNK file disguised as a folder.

T1036.008
Masquerade File Type
MalwareQakBot

The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.

T1036.008
Masquerade File Type
ToolBrute Ratel C4

Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.