T1036 - Masquerading
Tattiche:
Defense Evasion
Defense Evasion
Piattaforme:
Containers ESXi Linux macOS +1
Containers ESXi Linux macOS +1
Rilevamento:
Not specified
Not specified
Description:
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Renaming abusable system utilities to evade security monitoring is also a form of [Masquerading](https://attack.mitre.org/techniques/T1036).(Citation: LOLBAS Main Site)
Renaming abusable system utilities to evade security monitoring is also a form of [Masquerading](https://attack.mitre.org/techniques/T1036).(Citation: LOLBAS Main Site)
Sub-tecniche (12)
Usato da Attori (20)
APT28
Nation-state
Nation-state
OilRig
Nation-state
Nation-state
APT32
Nation-state
Nation-state
PLATINUM
Unknown
Unknown
WindShift
Unknown
Unknown
TeamTNT
Unknown
Unknown
FIN13
Unknown
Unknown
Aoqin Dragon
Unknown
Unknown
Winter Vivern
Unknown
Unknown
Sandworm Team
Unknown
Unknown
Ember Bear
Unknown
Unknown
BRONZE BUTLER
Unknown
Unknown
Storm-1811
Unknown
Unknown
menuPass
Unknown
Unknown
Contagious Interview
Unknown
Unknown
Agrius
Unknown
Unknown
TA551
Unknown
Unknown
Nomadic Octopus
Unknown
Unknown
ZIRCONIUM
Unknown
Unknown
LazyScripter
Unknown
Unknown
Malware (20)
TrickBot other
RCSession other
WindTail other
Pony other
UPSTYLE other
AppleSeed other
EnvyScout other
Dacls other
SombRAT other
WhisperGate other
Raindrop other
NotPetya other
Flagpro other
DarkTortilla other
BeaverTail other
DarkWatchman other
Bisonal other
DarkGate other
FoggyWeb other
Saint Bot other
Metadata
| MITRE ID: | T1036 |
| STIX ID: | attack-pattern--42e8de7b-37b2-... |
| Piattaforme: | Containers, ESXi, Linux, macOS, Windows |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |