FORENSIA

ATT&CK · T1036

Masquerading

Tactics: stealth

About

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.

Platforms: Containers, ESXi, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

20 known groups

Software

33 malware/tools implement this

RTMTrickBotBisonalNotPetyaRyukPonyRamsayWindTailDaclsRaindropSombRATAppleSeedEnvyScoutBoomBoxNativeZoneXCSSETFoggyWebRCSessionDarkWatchmanTrailBlazerWhisperGateFlagproMilanSaint BotPowGoopDarkTortillaDarkGateUPSTYLEStrelaStealerRedLine StealerBeaverTailGlassWormDynoWiper

Corpus indicators tagged with this technique

1,249 indicators in the corpus carry T1036.

IndicatorTypeFamilySevSrc
cve-2018-8007cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2024-1781cve851
cve-2020-22658cve852
cve-2017-17215cve852
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801
62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525sha256phishing802
771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97asha256phishing802
6c6cbed6aad96564ed87094785be07a1hashphishing802
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802
60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5casha256phishing802
a30a9779079dc897a15fed27f27f614fab77a20e953368808ba99ac6c6a3375bsha256phishing801
e4ccb2328c06710a7f0254cb6315e1b106396b0ff525f9cf3eada6e85d285c1csha256801
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802
221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9sha256801
43d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935sha256phishing802
23b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9sha256phishing802
bd46890121106b43f0c01ab82629400chashcryptojacking802
d35695f2366a43628231e73ffa83ca106306a8fahash802
82e579bd49d69845133c9aa8585f8bd26736437bhash802
f96bcd875836da89800912de1e557891697c7cf4hash802
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
fe0161fb8a26a0bf4afad746c7ebf89499dcd3a7hash802
9758e76b601798a30d903bf05052a53df80451e5c156548ce9da828f608b6470sha256801
5272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4sha256phishing802
50ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84sha256phishing802
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
5ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194sha256phishing802

Showing the top 30 by severity of 1,249.