T1036.005 - Match Legitimate Resource Name or Location
Sub-technique
Tactics:
Defense Evasion
Defense Evasion
Platforms:
Containers ESXi Linux macOS +1
Containers ESXi Linux macOS +1
Detection:
Not specified
Not specified
Description:
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.(Citation: Aquasec Kubernetes Backdoor 2023)
This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.(Citation: Aquasec Kubernetes Backdoor 2023)
Used by Actors (20)
APT1
Nation-state
Nation-state
DarkHotel
Nation-state
Nation-state
Naikon
Nation-state
Nation-state
APT28
Nation-state
Nation-state
APT29
Nation-state
Nation-state
Turla
Nation-state
Nation-state
FIN7
Criminal
Criminal
Lazarus Group
Nation-state
Nation-state
Poseidon Group
Unknown
Unknown
OilRig
Nation-state
Nation-state
PROMETHIUM
Unknown
Unknown
Gamaredon Group
Unknown
Unknown
APT32
Nation-state
Nation-state
APT5
Unknown
Unknown
Kimsuky
Nation-state
Nation-state
Sowbug
Nation-state
Nation-state
MuddyWater
Nation-state
Nation-state
MUSTANG PANDA
Nation-state
Nation-state
INDRIK SPIDER
Unknown
Unknown
APT39
Unknown
Unknown
Malware (20)
Metadata
| MITRE ID: | T1036.005 |
| STIX ID: | attack-pattern--1c4e5d32-1fe9-... |
| Platforms: | Containers, ESXi, Linux, macOS, Windows |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |