ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1036×

20 examples

TechniqueUsed byProcedure example
T1036
Masquerading
GroupmenuPass

menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files.

T1036
Masquerading
GroupAPT32

APT32 has disguised a Cobalt Strike beacon as a Flash Installer.

T1036
Masquerading
GroupStorm-1811

Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations.

T1036
Masquerading
GroupTeamTNT

TeamTNT has disguised their scripts with docker-related file names.

T1036
Masquerading
GroupSandworm Team

Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries.

T1036
Masquerading
GroupZIRCONIUM

ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware.

T1036
Masquerading
GroupContagious Interview

Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers.

T1036
Masquerading
GroupOilRig

OilRig has used .doc file extensions to mask malicious executables.

T1036
Masquerading
GroupAoqin Dragon

Aoqin Dragon has used fake icons including antivirus and external drives to disguise malicious payloads.

T1036
Masquerading
GroupWinter Vivern

Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns.

T1036
Masquerading
GroupBRONZE BUTLER

BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF.

T1036
Masquerading
GroupTA551

TA551 has masked malware DLLs as dat and jpg files.

T1036
Masquerading
GroupEmber Bear

Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as dump64.exe to evade detection.

T1036
Masquerading
GroupLazyScripter

LazyScripter has used several different security software icons to disguise executables.

T1036
Masquerading
GroupWindshift

Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers.

T1036
Masquerading
GroupAgrius

Agrius used the Plink tool for tunneling and connections to remote machines, renaming it systems.exe in some instances.

T1036
Masquerading
GroupAPT28

APT28 has renamed the WinRAR utility to avoid detection.

T1036
Masquerading
GroupPLATINUM

PLATINUM has renamed rar.exe to avoid detection.

T1036
Masquerading
GroupFIN13

FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file.

T1036
Masquerading
GroupNomadic Octopus

Nomadic Octopus attempted to make Octopus appear as a Telegram Messenger with a Russian interface.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.