T1036.003 Rename Legitimate Utilities
Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython.4576 It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename rundll32.exe).2 An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on these utilities executing from non-standard paths.3
| Item | Value |
|---|---|
| ID | T1036.003 |
| Sub-techniques | T1036.001, T1036.002, T1036.003, T1036.004, T1036.005, T1036.006, T1036.007, T1036.008, T1036.009, T1036.010, T1036.011, T1036.012 |
| Tactics | TA0005 |
| Platforms | Linux, Windows, macOS |
| Version | 2.0 |
| Created | 10 February 2020 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| G0050 | APT32 | APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection.14 |
| G0082 | APT38 | APT38 has renamed system utilities, such as rundll32.exe and mshta.exe, to avoid detection.15 |
| S0046 | CozyCar | The CozyCar dropper has masqueraded a copy of the infected system’s rundll32.exe executable that was moved to the malware’s install directory and renamed according to a predefined configuration file.3 |
| G1034 | Daggerfly | Daggerfly used a renamed version of rundll32.exe, such as “dbengin.exe” located in the ProgramData\Microsoft\PlayReady directory, to proxy malicious DLL execution.13 |
| S1111 | DarkGate | DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the C:\ root directory that copies and renames the legitimate Windows |
| G0093 | GALLIUM | GALLIUM used a renamed cmd.exe file to evade detection.16 |
| S1020 | Kevin | Kevin has renamed an image of cmd.exe with a random name followed by a .tmpl extension.10 |
| G0032 | Lazarus Group | Lazarus Group has renamed system utilities such as wscript.exe and mshta.exe.12 |
| G0045 | menuPass | menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool.11 |
| S1183 | StrelaStealer | StrelaStealer has used a renamed, legitimate msinfo32.exe executable to sideload the StrelaStealer payload during initial installation.8 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1022 | Restrict File and Directory Permissions | Use file system access controls to protect folders such as C:\Windows\System32. |
References
-
Carr, N.. (2018, October 25). Nick Carr Status Update Masquerading. Retrieved September 12, 2024. ↩
-
Ewing, P. (2016, October 31). How to Hunt: The Masquerade Ball. Retrieved October 31, 2016. ↩
-
F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015. ↩↩
-
LOLBAS. (n.d.). Living Off The Land Binaries and Scripts (and also Libraries). Retrieved February 10, 2020. ↩
-
Matthew Brennan. (2024, July 5). Snakes on a Domain: An Analysis of a Python Malware Loader. Retrieved April 3, 2025. ↩
-
Splunk. (2025, February 24). Detection: Detect Renamed PSExec. Retrieved April 3, 2025. ↩
-
The DFIR Report. (2023, February 6). Collect, Exfiltrate, Sleep, Repeat. Retrieved April 3, 2025. ↩
-
DCSO CyTec Blog. (2022, November 8). #ShortAndMalicious: StrelaStealer aims for mail credentials. Retrieved December 31, 2024. ↩
-
Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024. ↩
-
Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022. ↩
-
Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018. ↩
-
Pradhan, A. (2022, February 8). LolZarus: Lazarus Group Incorporating Lolbins into Campaigns. Retrieved March 22, 2022. ↩
-
Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024. ↩
-
Carr, N.. (2017, December 26). Nick Carr Status Update APT32 pubprn. Retrieved September 12, 2024. ↩
-
SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024. ↩
-
Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019. ↩