FORENSIA

ATT&CK · T1036.005 · sub-technique

Match Legitimate Resource Name or Location

Tactics: stealth

About

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.

Platforms: Containers, ESXi, Linux, macOS, WindowsParent: T1036 MasqueradingMITRE ATT&CK ↗

Used by actors

61 known groups

Software

140 malware/tools implement this

PlugXIxesheSslMMHTTPBrowserOwaAuthEliseMisdatMis-TypeS-TypeZLibRemsecBADNEWSUSBStealerOLDBAITWinnti for WindowsChChesFelismusFinFisherDaserfStarloaderPUNCHBUGGYNETWIREInnaputRATInvisiMoleBisonalQUADAGENTCalistoDarkCometOctopusNOKKIKONNIUrsnifLightNeuronOSX/ShlayerMacheteFysbisShimRatReporterRyukMetamorfoRamsayMechaFlounderSkidmapBackConfigGoopyBundloreIcedIDCarberpStrongPityGoldenSpyRDATREvilMCMDPipeMonBLINDINGCANKGH_SPYGrandoreiroSLOTHFULMEDIABazarSUNBURSTTEARDROPSUNSPOTRaindropDtrackSUPERNOVALookBackPysaTAINTEDSCRIBEPenquinGoldMaxSibotThiefQuestDokiEKANSBad RabbitAppleSeedCubaRainyDayNebulaeChaesMarkiRATFoggyWebThreatNeedleGelsemiumTinyTurlaKOCTOPUSCyclops BlinkGreen LambertDRATzarusHermeticWiperHermeticWizardTarraskDanBotOutSteelSaint BotSharkIceApplePyDCryptStrifeWaterSmall SieveBumblebeeChinoxySUGARDUMPPowGoopPcShareBrute Ratel C4Black BastaANDROMEDARotaJakiroQUIETEXITNightClubSamuraiNinjaSocGholishCuckoo StealerDUSTPANLatrodectusMagicRATStrelaStealerTroll StealerGoBearTRANSLATEXTJ-magicVIRTUALPITAPUBLOADCLAIMLOADERCANONSTAGERSTATICPLUGINTONESHELLQilinXORIndex LoaderHexEval LoaderShai-HuludBRICKSTORMPureCrypterSameCoinAshTagFooderTsundere BotnetLAMEHUGRustyWater

Corpus indicators tagged with this technique

1,428 indicators in the corpus carry T1036.005.

IndicatorTypeFamilySevSrc
cve-2026-3102cve853
d55ce447e249ef9045750865fa196c8ca8434c8c484f861b7bdecbceeab7c16esha256801
31f27fdc14505e0cebe360579e1ba0326762cbe0948e50b5f920da51fdef1b51hashphishing803
66bf111030a2e22db575c0b7b7b677208745eef8b44265bb4259f41f126f1bf8sha256801
512adab2c69feaf026adfb12cbd7d2eb4fee746120491e44f476eebddcbb19f2sha256801
a8acc24bb3e6a1a3b66a31ceaefda07d4a0e17415468683458b499f2ba240450sha256801
b032d4ec4e24714f59e853da9b6e63794aacdbcbhashphishing803
f79d05065a2ba7937b8781e69b5859d78d5f65f01fb291ae27d28277a5e37f9bhash801
2a350525ba72ffc9fe45a05a423833d5hashphishing802
ccca11a6d5835999c40a0a5264084b3740633600c157754fad2ef59559e31736sha256801
606966a9ec33765baedf63331595d1168f2a596fhash803
e5e43b0830369c39fab45363486da4d21a98c5097ea262c9816997f11c73c1c4hashphishing802
6328567511d88fdc2ae0939c5ef17b7a63d2a833881900de018a4f12f4982525sha256prompt_injection802
5a23ca644cb1f310be1abd5f6c6a3b3e15681ced99b0947a7f3465a79aae5089sha256801
83b7a106a5e810a1781e62b278909396hash801
37e065585c573ecc082aacbfd31564ebhashphishing803
1fc0a876a121882ffaad6677f444cf5bhash801
86db2530298e6335d3ecc66c2818cfbd0a6b11fcdfcb75f575b9fcce1faa00f1hash801
4ce45e016a304d813e67b29a08265b2101c2e15a09ace5de6539cad02567affesha256supply_chain801
0d681bd160db1b1df5db321a6d2dd9ae81b2609bhash801
ced6b0f4441085bb9c54a32da9ab4ba14c6e21daf6e34fd61d54923f87baacd0hashphishing803
cd4a51037bf58733c0cb24b273951dd3fcea45a2aaeb8b30a3c625e183c4c0c7hashphishing802
25b6fc4f9c54a28ba7bfc4dfeafb62c99b59ea6f0d17679219b876b321965095sha256phishing801
067ad6221b2224d5cdb64e51c5516132d820cf4d7edf9ec170643943e79c04b7sha256phishing801
d6f479736ba55d3c4e895c4940d035cf772f3192fb8dc496f09a801aed16d970sha256phishing801
833008c03d40422192051584d829d730497108bef31751cceb0cc043dd96bbfbsha256phishing801
8111edf01ac6cb5c77e249d4e84fd92a85b5e89c2e2bef92fbe00b6f1cc2aa8esha256phishing801
f0038a5f46720da5982b6984ceef10cf99359432e102b12a0b0657498d36f670sha256phishing801
dce5df29bddff5a4ddaea5c4fec14da91f7b69063a6e1c45ed61e5da4fc6c87bsha256802
7d8b6a64f7b65b281e7b5568929c6f96c62bbae9628162aabe7d8140a86d3de8sha256801

Showing the top 30 by severity of 1,428.