Masquerade Task or Service

T1036.004

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.

Tasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.

Detection rules2

Rules on DetectionCode tagged with T1036.004.

Sigma1

RuleLevelLog source
Scheduled Task Creation Masquerading as System Processeshighwindows / process_creation

Splunk1

RuleTypeRiskData source
Linux Kworker Process In Writable Process PathHuntingNULLSysmon for Linux EventID 1

Groups23

Software63

Show 39 more

Campaigns7

Procedure examples93

Groups23

Used byProcedure example
GroupAPT-C-36

APT-C-36 has disguised its scheduled tasks as those used by Google.

GroupAPT32

APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe".

GroupAPT41

APT41 has created services to appear as benign system tools.

GroupAquatic Panda

Aquatic Panda created new, malicious services using names such as Windows User Service to attempt to blend in with legitimate items on victim systems.

GroupBackdoorDiplomacy

BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations.

GroupBITTER

BITTER has disguised malware as a Windows Security update service.

GroupCarbanak

Carbanak has copied legitimate service names to use for malicious services.

GroupFIN13

FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory.

View all 23 groups examples

Software63

Used byProcedure example
MalwareAttor

Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate).

MalwareBazar

Bazar can create a task named to appear benign.

MalwareBlack Basta

Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name.

MalwareBOOKWORM

BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`.

Malwarebuild_downer

build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate.

MalwareCanisterWorm

CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon.

MalwareCatchamas

Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service.

MalwareComRAT

ComRAT has used a task name associated with Windows SQM Consolidator.

View all 63 software examples

Campaigns7

Used byProcedure example
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Systemd service units to masquerade GOGETTER malware as legitimate or seemingly legitimate services.

CampaignAPT41 DUST

APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

CampaignC0017

During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code.

CampaignFrankenstein

During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence.

CampaignKV Botnet Activity

KV Botnet Activity installation steps include first identifying, then stopping, any process containing [kworker\/0:1], then renaming its initial installation stage to this process name.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda masqueraded Registry run keys as legitimate-looking service names such as `OneNote Update` during RedDelta Modified PlugX Infection Chain Operations.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate.

References4

  1. Fysbis Dr Web Analysis Open source
    Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017.
  2. Palo Alto Shamoon Nov 2016 Open source
    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.
  3. Systemd Service Units Open source
    Freedesktop.org. (n.d.). systemd.service — Service unit configuration. Retrieved March 16, 2020.
  4. TechNet Schtasks Open source
    Microsoft. (n.d.). Schtasks. Retrieved April 28, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.