Masquerade File Type

T1036.008

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file’s signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file’s type. For example, the header of a JPEG file, is 0xFF 0xD8 and the file extension is either `.JPE`, `.JPEG` or `.JPG`.

Adversaries may edit the header’s hex code and/or the file extension of a malicious payload in order to bypass file validation checks and/or input sanitization. This behavior is commonly used when payload files are transferred (e.g., Ingress Tool Transfer) and stored (e.g., Upload Malware) so that adversaries may move their malware without triggering detections.

Common non-executable file types and extensions, such as text files (`.txt`) and image files (`.jpg`, `.gif`, etc.) may be typically treated as benign. Based on this, adversaries may use a file extension to disguise malware, such as naming a PHP backdoor code with a file name of test.gif. A user may not know that a file is malicious due to the benign appearance and file extension.

Polyglot files, which are files that have multiple different file types and that function differently based on the application that will execute them, may also be used to disguise malicious malware and capabilities.

Detection rules3

Rules on DetectionCode tagged with T1036.008.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk3

RuleTypeRiskData source
Email Attachments With Lots Of SpacesAnomalyNULL
Suspicious Process Executed From Container FileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Executable Masquerading as Benign File TypesAnomalyNULLSysmon EventID 29

Groups4

Software13

Campaigns3

Procedure examples20

Groups4

Used byProcedure example
GroupBlackByte

BlackByte masqueraded configuration files containing encryption keys as PNG files.

GroupMirrorFace

MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files.

GroupMustang Panda

Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware.

GroupVolt Typhoon

Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension.

Software13

Used byProcedure example
MalwareANDROMEDA

ANDROMEDA has been delivered through a LNK file disguised as a folder.

MalwareAvosLocker

AvosLocker has been disguised as a .jpg file.

ToolBrute Ratel C4

Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files.

MalwareHeartCrypt

HeartCrypt can append a BMP header to encoded malicious payloads to masquerade them as BMP files.

MalwareKapeka

Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file.

MalwareLumma Stealer

Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content.

MalwareMagicRAT

MagicRAT can download additional executable payloads that masquerade as GIF files.

MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has disguised it's true file structure as an application bundle by adding special characters to the filename and using the icon for legitimate Word documents.

View all 13 software examples

Campaigns3

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as `.txt` files.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection.

References1

  1. polygot_icedID Open source
    Lim, M. (2022, September 27). More Than Meets the Eye: Exposing a Polyglot File That Delivers IcedID. Retrieved September 29, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.