Technique with 12 sub-techniques.View on attack.mitre.org
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.
Rules on DetectionCode tagged with T1036 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Attacker Tools On Endpoint | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1036.005 |
| Cisco NVM - Non-Network Binary Making Network Connection | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1036 |
| Detect RTLO In File Name | TTP | NULL | Sysmon EventID 11 | T1036.002 |
| Detect RTLO In Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.002 |
| Email Attachments With Lots Of Spaces | Anomaly | NULL | T1036.008 | |
| Executables Or Script Creation In Suspicious Path | Anomaly | NULL | Sysmon EventID 11 | T1036 |
| Executables Or Script Creation In Temp Path | Anomaly | NULL | Sysmon EventID 11 | T1036 |
| Execution of File with Multiple Extensions | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Execution of File With Spaces Before Extension | TTP | NULL | Sysmon EventID 1 | T1036.003 |
| Linux Kworker Process In Writable Process Path | Hunting | NULL | Sysmon for Linux EventID 1 | T1036.004 |
| Linux Possible System Binary Backdoor | Anomaly | NULL | Sysmon for Linux EventID 11 | T1036 |
| Linux Suspicious Staging of Alternate System Files | Anomaly | NULL | Sysmon for Linux EventID 11 | T1036 |
| Suspicious Copy on System32 | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Suspicious microsoft workflow compiler rename | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Suspicious msbuild path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Suspicious MSBuild Rename | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Suspicious Process Executed From Container File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.008 |
| Suspicious Rundll32 Rename | Hunting | NULL | Sysmon EventID 1 | T1036.003 |
| Suspicious writes to System Volume Information | Hunting | NULL | Sysmon EventID 1 | T1036 |
| Suspicious writes to windows Recycle Bin | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11 | T1036 |
| System Processes Run From Unexpected Locations | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Windows Bluetooth Service Installed From Uncommon Location | Anomaly | NULL | Windows Event Log System 7045 | T1036 |
| Windows Builtin Account Name Was Changed | TTP | NULL | Windows Event Log Security 4781 | T1036.010 |
| Windows Debugger Tool Execution | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036 |
| Windows DotNet Binary in Non Standard Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Windows Executable Masquerading as Benign File Types | Anomaly | NULL | Sysmon EventID 29 | T1036.008 |
| Windows InstallUtil in Non Standard Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Windows LOLBAS Executed As Renamed File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.003 |
| Windows LOLBAS Executed Outside Expected Path | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1036.005 |
| Windows Masquerading Msdtc Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036 |
| Windows MSC EvilTwin Directory Path Manipulation | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.005 |
| Windows NetSupport RMM DLL Loaded By Uncommon Process | Anomaly | NULL | Sysmon EventID 7 | T1036 |
| Windows Process Execution From ProgramData | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.005 |
| Windows Process Execution in Temp Dir | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.005 |
| Windows Renamed Powershell Execution | TTP | NULL | Sysmon EventID 1 | T1036.003 |
| Windows SoftEther VPN Masquerading as Legitimate Binary | TTP | NULL | Sysmon EventID 1 | T1036 |
| Windows Suspicious Process File Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1036.005 |
| Windows Suspicious QEMU Execution | TTP | NULL | Sysmon EventID 1 | T1036 |
| Windows Svchost.exe Parent Process Anomaly | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1036.009 |
| Windows TinyCC Shellcode Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1036 |
| Windows Unusual SysWOW64 Process Run System32 Executable | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1036.009 |
| ID | Name | Examples |
|---|---|---|
| T1036.001 | Invalid Code Signature | 9 |
| T1036.002 | Right-to-Left Override | 5 |
| T1036.003 | Rename Legitimate Utilities | 11 |
| T1036.004 | Masquerade Task or Service | 93 |
| T1036.005 | Match Legitimate Resource Name or Location | 221 |
| T1036.006 | Space after Filename | 2 |
| T1036.007 | Double File Extension | 5 |
| T1036.008 | Masquerade File Type | 20 |
| T1036.009 | Break Process Trees | 2 |
| T1036.010 | Masquerade Account Name | 7 |
| T1036.011 | Overwrite Process Arguments | 1 |
| T1036.012 | Browser Fingerprint | 1 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius used the Plink tool for tunneling and connections to remote machines, renaming it |
| GroupAoqin Dragon | Aoqin Dragon has used fake icons including antivirus and external drives to disguise malicious payloads. |
| GroupAPT28 | APT28 has renamed the WinRAR utility to avoid detection. |
| GroupAPT32 | APT32 has disguised a Cobalt Strike beacon as a Flash Installer. |
| GroupBRONZE BUTLER | BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF. |
| GroupContagious Interview | Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Sekoia ClickFake 2025Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| GroupEmber Bear | Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as |
| GroupFIN13 | FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file. |
| Used by | Procedure example |
|---|---|
| MalwareAppleSeed | AppleSeed can disguise JavaScript files as PDFs. |
| MalwareBeaverTail | BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes. |
| MalwareBisonal | Bisonal dropped a decoy payload with a .jpg extension that contained a malicious Visual Basic script. |
| MalwareBoomBox | BoomBox has the ability to mask malicious data strings as PDF files. |
| MalwareDacls | The Dacls Mach-O binary has been disguised as a .nib file. |
| MalwareDarkGate | DarkGate can masquerade as pirated media content for initial delivery to victims. |
| MalwareDarkTortilla | DarkTortilla's payload has been renamed `PowerShellInfo.exe`. |
| MalwareDarkWatchman | DarkWatchman has used an icon mimicking a text file to mask a malicious executable. |
| Used by | Procedure example |
|---|---|
| CampaignArcaneDoor | ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances. |
| CampaignC0015 | During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file. |
| CampaignC0018 | During C0018, AvosLocker was disguised using the victim company name as the filename. |
| CampaignKV Botnet Activity | KV Botnet Activity involves changing process filename to |
| CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors disguised some executables as JPG files. |
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document. |
| CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used voice calls to socially engineer victims into authorizing a modified version of the Salesforce Data Loader app. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.