FORENSIA

ATT&CK · T1036.003 · sub-technique

Rename Legitimate Utilities

Tactics: stealth

About

Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename <code>rundll32.exe</code>). An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on these utilities executing from non-standard paths.

Platforms: Linux, macOS, WindowsParent: T1036 MasqueradingMITRE ATT&CK ↗

Used by actors

6 known groups

Software

5 malware/tools implement this

CozyCarKevinDarkGateStrelaStealerPHASEJAM

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1036.003.

No corpus indicators are tagged with this technique yet.