Browser Fingerprint

T1036.012

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc. The HTTP User-Agent request header is a string that lets servers and network peers identify the application, operating system, vendor, and/or version of the requesting user agent.

Adversaries may gather this information through System Information Discovery or by users navigating to adversary-controlled websites, and then use that information to craft their web traffic to evade defenses.

Detection rules0

Rules on DetectionCode tagged with T1036.012.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwareFatDuke

FatDuke has attempted to mimic a compromised user's traffic by using the same user agent as the installed browser.

References2

  1. Gummy Browsers Targeted Browser Spoofing against State-of-the-Art Fingerprinting Techniques Open source
    Zengrui Liu, Prakash Shrestha, and Nitesh Saxena. (2021, October 19). Retrieved April 15, 2026.
  2. Mozilla User Agent Open source
    MDN contributors. (2025, July 4). User-Agent header. Retrieved October 19, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.