Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.008 Masquerade File Type |
MalwareAvosLocker | AvosLocker has been disguised as a .jpg file. |
| T1036.008 Masquerade File Type |
MalwareHeartCrypt | HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files. |
| T1036.008 Masquerade File Type |
MalwareSTATICPLUGIN | STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension. |
| T1036.008 Masquerade File Type |
MalwareRaspberry Robin | Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder. |
| T1036.008 Masquerade File Type |
MalwareLumma Stealer | Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content. |
| T1036.008 Masquerade File Type |
MalwarePureCrypter | PureCrypter has used a .NET downloader named 63342221.BAT and has used .jpg, .png, and .log as false extensions for malicious files. |
| T1036.008 Masquerade File Type |
MalwareMagicRAT | MagicRAT can download additional executable payloads that masquerade as GIF files. |
| T1036.008 Masquerade File Type |
MalwareStrelaStealer | StrelaStealer has been distributed as a DLL/HTML polyglot file. |
| T1036.008 Masquerade File Type |
MalwareKapeka | Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file. |
| T1036.008 Masquerade File Type |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents. |
| T1036.008 Masquerade File Type |
MalwareANDROMEDA | ANDROMEDA has been delivered through a LNK file disguised as a folder. |
| T1036.008 Masquerade File Type |
MalwareQakBot | The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon. |
| T1036.008 Masquerade File Type |
ToolBrute Ratel C4 | Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.