Sub-technique of T1036 Masquerading.View on attack.mitre.org
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.
Tasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.
Rules on DetectionCode tagged with T1036.004.
| Rule | Level | Log source |
|---|---|---|
| Scheduled Task Creation Masquerading as System Processes | high | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux Kworker Process In Writable Process Path | Hunting | NULL | Sysmon for Linux EventID 1 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has disguised its scheduled tasks as those used by Google. |
| GroupAPT32 | APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe". |
| GroupAPT41 | APT41 has created services to appear as benign system tools. |
| GroupAquatic Panda | Aquatic Panda created new, malicious services using names such as |
| GroupBackdoorDiplomacy | BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations. |
| GroupBITTER | BITTER has disguised malware as a Windows Security update service. |
| GroupCarbanak | Carbanak has copied legitimate service names to use for malicious services. |
| GroupFIN13 | FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory. |
| Used by | Procedure example |
|---|---|
| MalwareAttor | Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate). |
| MalwareBazar | Bazar can create a task named to appear benign. |
| MalwareBlack Basta | Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name. |
| MalwareBOOKWORM | BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`. |
| Malwarebuild_downer | build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate. |
| MalwareCanisterWorm | CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon. |
| MalwareCatchamas | Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service. |
| MalwareComRAT | ComRAT has used a task name associated with Windows SQM Consolidator. |
| Used by | Procedure example |
|---|---|
| Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Systemd service units to masquerade GOGETTER malware as legitimate or seemingly legitimate services. |
| CampaignAPT41 DUST | APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| CampaignC0017 | During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code. |
| CampaignFrankenstein | During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence. |
| CampaignKV Botnet Activity | KV Botnet Activity installation steps include first identifying, then stopping, any process containing |
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda masqueraded Registry run keys as legitimate-looking service names such as `OneNote Update` during RedDelta Modified PlugX Infection Chain Operations. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.