Sub-technique of T1036 Masquerading.View on attack.mitre.org
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.
Rules on DetectionCode tagged with T1036.005.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Attacker Tools On Endpoint | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows LOLBAS Executed Outside Expected Path | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows MSC EvilTwin Directory Path Manipulation | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Process Execution From ProgramData | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Process Execution in Temp Dir | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Suspicious Process File Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 actors used the following command to rename one of their tools to a benign file name: |
| GroupAkira | Akira has used legitimate names and locations for files to evade defenses. |
| GroupAPT-C-36 | APT-C-36 has disguised malicious executables to appear as legitimate files. |
| GroupAPT1 | The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware. |
| GroupAPT28 | APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page. |
| GroupAPT29 | APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal. |
| GroupAPT32 | APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. |
| GroupAPT39 | APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe. |
| Used by | Procedure example |
|---|---|
| MalwareANDROMEDA | ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service. |
| MalwareAppleSeed | AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity. |
| MalwareAshTag | AshTag has masqueraded as a legitimate VisualServer utility. |
| MalwareBackConfig | BackConfig has hidden malicious payloads in |
| MalwareBad Rabbit | Bad Rabbit has masqueraded as a Flash Player installer through the executable file |
| MalwareBADNEWS | BADNEWS attempts to hide its payloads using legitimate filenames. |
| MalwareBazar | The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software. |
| MalwareBisonal | Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`. |
View all 143 software examples
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files. |
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection. |
| CampaignC0017 | During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections. |
| CampaignC0018 | For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe. |
| CampaignJ-magic Campaign | During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.