Match Legitimate Resource Name or Location

T1036.005

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.

Detection rules23

Rules on DetectionCode tagged with T1036.005.

Sigma17

RuleLevelLog source
Flash Player Update from Suspicious LocationhighNULL / proxy
Potential MsiExec Masqueradinghighwindows / process_creation
Scheduled Task Creation Masquerading as System Processeshighwindows / process_creation
Suspicious Process Masquerading As SvcHost.EXEhighwindows / process_creation
Suspicious WSL Binary Hijack via Proxy Executionhighwindows / process_creation
Suspicious WSL Binary Masqueradinghighwindows / process_creation
Uncommon Svchost Command Line Parameterhighwindows / process_creation
Creation Of Pod In System Namespacemediumkubernetes / application
Files With System DLL Name In Unsuspected Locationsmediumwindows / file_event
Files With System Process Name In Unsuspected Locationsmediumwindows / file_event
Potential Binary Impersonating Sysinternals Toolsmediumwindows / process_creation
Potential WSL Binary Modification from Installed Locationmediumwindows / file_event
Suspicious Files in Default GPO Foldermediumwindows / file_event
Suspicious Scheduled Task Creation via Masqueraded XML Filemediumwindows / process_creation
Uncommon Svchost Parent Processmediumwindows / process_creation

Splunk6

RuleTypeRiskData source
Attacker Tools On EndpointTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data
Windows LOLBAS Executed Outside Expected PathAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688
Windows MSC EvilTwin Directory Path ManipulationTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Process Execution From ProgramDataHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Process Execution in Temp DirAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Suspicious Process File PathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups63

Show 39 more

Software143

Show 119 more

Campaigns15

Procedure examples221

Groups63

Used byProcedure example
Groupadmin@338

admin@338 actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe

GroupAkira

Akira has used legitimate names and locations for files to evade defenses.

GroupAPT-C-36

APT-C-36 has disguised malicious executables to appear as legitimate files.

GroupAPT1

The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware.

GroupAPT28

APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page.

GroupAPT29

APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal.

GroupAPT32

APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.

GroupAPT39

APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe.

View all 63 groups examples

Software143

Used byProcedure example
MalwareANDROMEDA

ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service.

MalwareAppleSeed

AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity.

MalwareAshTag

AshTag has masqueraded as a legitimate VisualServer utility.

MalwareBackConfig

BackConfig has hidden malicious payloads in %USERPROFILE%\Adobe\Driver\dwg\ and mimicked the legitimate DHCP service binary.

MalwareBad Rabbit

Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.

MalwareBADNEWS

BADNEWS attempts to hide its payloads using legitimate filenames.

MalwareBazar

The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software.

MalwareBisonal

Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`.

View all 143 software examples

Campaigns15

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection.

CampaignC0017

During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections.

CampaignC0018

For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`.

CampaignC0032

During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.

CampaignHomeLand Justice

During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.

CampaignJ-magic Campaign

During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files.

View all 15 campaigns examples

References1

  1. Aquasec Kubernetes Backdoor 2023 Open source
    Michael Katchinskiy and Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved March 24, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.