Skip to content

T1036.003 Rename Legitimate Utilities

Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython.4576 It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename rundll32.exe).2 An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on these utilities executing from non-standard paths.3

Item Value
ID T1036.003
Sub-techniques T1036.001, T1036.002, T1036.003, T1036.004, T1036.005, T1036.006, T1036.007, T1036.008, T1036.009, T1036.010, T1036.011, T1036.012
Tactics TA0005
Platforms Linux, Windows, macOS
Version 2.0
Created 10 February 2020
Last Modified 24 October 2025

Procedure Examples

ID Name Description
G0050 APT32 APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection.14
G0082 APT38 APT38 has renamed system utilities, such as rundll32.exe and mshta.exe, to avoid detection.15
S0046 CozyCar The CozyCar dropper has masqueraded a copy of the infected system’s rundll32.exe executable that was moved to the malware’s install directory and renamed according to a predefined configuration file.3
G1034 Daggerfly Daggerfly used a renamed version of rundll32.exe, such as “dbengin.exe” located in the ProgramData\Microsoft\PlayReady directory, to proxy malicious DLL execution.13
S1111 DarkGate DarkGate executes a Windows Batch script during installation that creases a randomly-named directory in the C:\ root directory that copies and renames the legitimate Windows curl command to this new location.9
G0093 GALLIUM GALLIUM used a renamed cmd.exe file to evade detection.16
S1020 Kevin Kevin has renamed an image of cmd.exe with a random name followed by a .tmpl extension.10
G0032 Lazarus Group Lazarus Group has renamed system utilities such as wscript.exe and mshta.exe.12
G0045 menuPass menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool.11
S1183 StrelaStealer StrelaStealer has used a renamed, legitimate msinfo32.exe executable to sideload the StrelaStealer payload during initial installation.8

Mitigations

ID Mitigation Description
M1022 Restrict File and Directory Permissions Use file system access controls to protect folders such as C:\Windows\System32.

References


  1. Carr, N.. (2018, October 25). Nick Carr Status Update Masquerading. Retrieved September 12, 2024. ↩

  2. Ewing, P. (2016, October 31). How to Hunt: The Masquerade Ball. Retrieved October 31, 2016. ↩

  3. F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015. ↩↩

  4. LOLBAS. (n.d.). Living Off The Land Binaries and Scripts (and also Libraries). Retrieved February 10, 2020. ↩

  5. Matthew Brennan. (2024, July 5). Snakes on a Domain: An Analysis of a Python Malware Loader. Retrieved April 3, 2025. ↩

  6. Splunk. (2025, February 24). Detection: Detect Renamed PSExec. Retrieved April 3, 2025. ↩

  7. The DFIR Report. (2023, February 6). Collect, Exfiltrate, Sleep, Repeat. Retrieved April 3, 2025. ↩

  8. DCSO CyTec Blog. (2022, November 8). #ShortAndMalicious: StrelaStealer aims for mail credentials. Retrieved December 31, 2024. ↩

  9. Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024. ↩

  10. Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022. ↩

  11. Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018. ↩

  12. Pradhan, A. (2022, February 8). LolZarus: Lazarus Group Incorporating Lolbins into Campaigns. Retrieved March 22, 2022. ↩

  13. Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024. ↩

  14. Carr, N.. (2017, December 26). Nick Carr Status Update APT32 pubprn. Retrieved September 12, 2024. ↩

  15. SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024. ↩

  16. Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019. ↩