Masquerading

T1036

Technique with 12 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.

Detection rules126

Rules on DetectionCode tagged with T1036 or one of its sub-techniques.

Sigma85

RuleLevelLog sourceTechnique
CreateDump Process Dumphighwindows / process_creationT1036
File Download Via Bitsadmin To A Suspicious Target Folderhighwindows / process_creationT1036.003
File With Suspicious Extension Downloaded Via Bitsadminhighwindows / process_creationT1036.003
Flash Player Update from Suspicious LocationhighNULL / proxyT1036.005
Forfiles.EXE Child Process Masqueradinghighwindows / process_creationT1036
HackTool - XORDump Executionhighwindows / process_creationT1036
LOL-Binary Copied From System Directoryhighwindows / process_creationT1036.003
MMC Executing Files with Reversed Extensions Using RTLO Abusehighwindows / process_creationT1036.002
Password Protected ZIP File Opened (Suspicious Filenames)highwindows / NULLT1036
Potential Defense Evasion Via Rename Of Highly Relevant Binarieshighwindows / process_creationT1036.003
Potential Defense Evasion Via Right-to-Left Overridehighwindows / process_creationT1036.002
Potential File Extension Spoofing Using Right-to-Left Overridehighwindows / file_eventT1036.002
Potential LSASS Process Dump Via Procdumphighwindows / process_creationT1036
Potential MsiExec Masqueradinghighwindows / process_creationT1036.005
Potential SysInternals ProcDump Evasionhighwindows / process_creationT1036

Splunk41

RuleTypeRiskData sourceTechnique
Attacker Tools On EndpointTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow DataT1036.005
Cisco NVM - Non-Network Binary Making Network ConnectionAnomalyNULLCisco Network Visibility Module Flow DataT1036
Detect RTLO In File NameTTPNULLSysmon EventID 11T1036.002
Detect RTLO In ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1036.002
Email Attachments With Lots Of SpacesAnomalyNULLT1036.008
Executables Or Script Creation In Suspicious PathAnomalyNULLSysmon EventID 11T1036
Executables Or Script Creation In Temp PathAnomalyNULLSysmon EventID 11T1036
Execution of File with Multiple ExtensionsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1036.003
Execution of File With Spaces Before ExtensionTTPNULLSysmon EventID 1T1036.003
Linux Kworker Process In Writable Process PathHuntingNULLSysmon for Linux EventID 1T1036.004
Linux Possible System Binary BackdoorAnomalyNULLSysmon for Linux EventID 11T1036
Linux Suspicious Staging of Alternate System FilesAnomalyNULLSysmon for Linux EventID 11T1036
Suspicious Copy on System32AnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1036.003
Suspicious microsoft workflow compiler renameHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1036.003
Suspicious msbuild pathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1036.003

Sub-techniques12

IDNameExamples
T1036.001Invalid Code Signature9
T1036.002Right-to-Left Override5
T1036.003Rename Legitimate Utilities11
T1036.004Masquerade Task or Service93
T1036.005Match Legitimate Resource Name or Location221
T1036.006Space after Filename2
T1036.007Double File Extension5
T1036.008Masquerade File Type20
T1036.009Break Process Trees2
T1036.010Masquerade Account Name7
T1036.011Overwrite Process Arguments1
T1036.012Browser Fingerprint1

Groups20

Software33

Show 9 more

Campaigns7

Procedure examples60

Groups20

Used byProcedure example
GroupAgrius

Agrius used the Plink tool for tunneling and connections to remote machines, renaming it systems.exe in some instances.

GroupAoqin Dragon

Aoqin Dragon has used fake icons including antivirus and external drives to disguise malicious payloads.

GroupAPT28

APT28 has renamed the WinRAR utility to avoid detection.

GroupAPT32

APT32 has disguised a Cobalt Strike beacon as a Flash Installer.

GroupBRONZE BUTLER

BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF.

GroupContagious Interview

Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers.

GroupEmber Bear

Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as dump64.exe to evade detection.

GroupFIN13

FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file.

View all 20 groups examples

Software33

Used byProcedure example
MalwareAppleSeed

AppleSeed can disguise JavaScript files as PDFs.

MalwareBeaverTail

BeaverTail has masqueraded as MiroTalk installation packages: “MiroTalk.dmg” for macOS and “MiroTalk.msi” for Windows, and has included login GUIs with MiroTalk themes.

MalwareBisonal

Bisonal dropped a decoy payload with a .jpg extension that contained a malicious Visual Basic script.

MalwareBoomBox

BoomBox has the ability to mask malicious data strings as PDF files.

MalwareDacls

The Dacls Mach-O binary has been disguised as a .nib file.

MalwareDarkGate

DarkGate can masquerade as pirated media content for initial delivery to victims.

MalwareDarkTortilla

DarkTortilla's payload has been renamed `PowerShellInfo.exe`.

MalwareDarkWatchman

DarkWatchman has used an icon mimicking a text file to mask a malicious executable.

View all 33 software examples

Campaigns7

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances.

CampaignC0015

During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file.

CampaignC0018

During C0018, AvosLocker was disguised using the victim company name as the filename.

CampaignKV Botnet Activity

KV Botnet Activity involves changing process filename to pr_set_mm_exe_file and process name to pr_set_name during later infection stages.

CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors disguised some executables as JPG files.

CampaignOperation Honeybee

During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document.

CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used voice calls to socially engineer victims into authorizing a modified version of the Salesforce Data Loader app.

References1

  1. LOLBAS Main Site Open source
    LOLBAS. (n.d.). Living Off The Land Binaries and Scripts (and also Libraries). Retrieved February 10, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.