FORENSIA

ATT&CK · T1036.004 · sub-technique

Masquerade Task or Service

Tactics: stealth

About

Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones. Tasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.

Platforms: Linux, macOS, WindowsParent: T1036 MasqueradingMITRE ATT&CK ↗

Used by actors

23 known groups

Software

62 malware/tools implement this

PlugXUroburosNidiranComRATShamoonRTMRawPOSTruvasysVolgmerPOWERSTATSKwampirsInnaputRATInvisiMoleCatchamasExaramel for WindowsSeasaltOSX_OCEANLOTUS.DKONNIEmotetMacheteFysbisAttorOkrumShimRatMazebuild_downerStrongPityRDATCSPY DownloaderSLOTHFULMEDIABazarCrutchEgregorIronNetInjectorGoldMaxHildegardKillDiskRainyDayNebulaeTurianSysUpdateTinyTurlaMeteorGreen LambertTarraskZxxZHeyoka BackdoorPingPullDCSrvSUGARDUMPFunnyDreamDEADEYESVCReadyBlack BastaNightClubRaspberry RobinDEADWOODSpicaVIRTUALPITABOOKWORMTONESHELLQilin

Corpus indicators tagged with this technique

75 indicators in the corpus carry T1036.004.