Skip to content

T1036.005 Match Legitimate Resource Name or Location

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.4

Item Value
ID T1036.005
Sub-techniques T1036.001, T1036.002, T1036.003, T1036.004, T1036.005, T1036.006, T1036.007, T1036.008, T1036.009, T1036.010, T1036.011, T1036.012
Tactics TA0005
Platforms Containers, ESXi, Linux, Windows, macOS
Version 2.0
Created 10 February 2020
Last Modified 24 October 2025

Procedure Examples

ID Name Description
C0025 2016 Ukraine Electric Power Attack During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.223
G0018 admin@338 admin@338 actors used the following command to rename one of their tools to a benign file name: ren “%temp%\upload” audiodg.exe174
G1024 Akira Akira has used legitimate names and locations for files to evade defenses.177
S1074 ANDROMEDA ANDROMEDA has been installed to C:\Temp\TrustedInstaller.exe to mimic a legitimate Windows installer service.43
S0622 AppleSeed AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity.67
G0006 APT1 The file name AcroRD32.exe, a legitimate process name for Adobe’s Acrobat Reader, was used by APT1 as a name for malware.202201
G0007 APT28 APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page.182
G0016 APT29 APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal.181180
G0050 APT32 APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. 136185
G0087 APT39 APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe.208207
G0096 APT41 APT41 attempted to masquerade their files as popular anti-virus software.159160
G1044 APT42 APT42 has masqueraded the VINETHORN payload as a VPN application.161
G1023 APT5 APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a KB<digits>.zip pattern.212
G0143 Aquatic Panda Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments.184
S0475 BackConfig BackConfig has hidden malicious payloads in %USERPROFILE%\Adobe\Driver\dwg\ and mimicked the legitimate DHCP service binary.139
G0135 BackdoorDiplomacy BackdoorDiplomacy has dropped implants in folders named for legitimate software.176
S0606 Bad Rabbit Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.4849
S0128 BADNEWS BADNEWS attempts to hide its payloads using legitimate filenames.114
S0534 Bazar The Bazar loader has named malicious shortcuts “adobe” and mimicked communications software.777879
S0268 Bisonal Bisonal has renamed malicious code to msacm32.dll to hide within a legitimate library; earlier versions were disguised as winhelp.137
S1070 Black Basta The Black Basta dropper has mimicked an application for creating USB bootable drivers.129
S0520 BLINDINGCAN BLINDINGCAN has attempted to hide its payload by using legitimate file names such as “iconcache.db”.38
G0108 Blue Mockingbird Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file.203
G0060 BRONZE BUTLER BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems.157
S1063 Brute Ratel C4 Brute Ratel C4 has used a payload file named OneDrive.update to appear benign.6
S1039 Bumblebee Bumblebee has named component DLLs “RapportGP.dll” to match those used by the security company Trusteer.82
S0482 Bundlore Bundlore has disguised a malicious .app file as a Flash Player update.18
C0017 C0017 During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections.229
C0018 C0018 For C0018, the threat actors renamed a Sliver payload to vmware_kb.exe.224
C0032 C0032 During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.227
S0274 Calisto Calisto’s installation file is an unsigned DMG image under the guise of Intego’s security solution for mac.122
S1237 CANONSTAGER CANONSTAGER has leveraged naming conventions of its malicious DLL to match legitimate services to include cnmpaui.dll which matches the legitimate executable cnmpaui.exe that is aligned with a Canon Ink Jet Printer Assistant Tool.61
G0008 Carbanak Carbanak has named malware “svchost.exe,” which is the name of the Windows shared service host program.198
S0484 Carberp Carberp has masqueraded as Windows system file names, as well as “chkntfs.exe” and “syscron.exe”.2324
S0631 Chaes Chaes has used an unsigned, crafted DLL module named hha.dll that was designed to look like a legitimate 32-bit Windows DLL.99
S0144 ChChes ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe).133
G0114 Chimera Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe.183
S1041 Chinoxy Chinoxy has used the name eoffice.exe in attempt to appear as a legitimate file.5
S1236 CLAIMLOADER CLAIMLOADER has imitated legitimate software directories through the creation and storage of the EXE and DLL in C:\ProgramData\ and the use of legitimate looking names of software.83
S0625 Cuba Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs.140
S1153 Cuckoo Stealer
Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter.7374
S0687 Cyclops Blink Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread. Cyclops Blink has also named RC scripts used for persistence after WatchGuard artifacts.20
S1014 DanBot DanBot files have been named UltraVNC.exe and WINVNC.exe to appear as legitimate VNC tools.19
S0334 DarkComet DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file.146
G0012 Darkhotel Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool.200
S0187 Daserf Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs.124
S0600 Doki Doki has disguised a file as a Linux kernel module.111
S0694 DRATzarus DRATzarus has been named Flash.exe, and its dropper has been named IExplorer.81
S0567 Dtrack One of Dtrack can hide in replicas of legitimate programs like OllyDbg, 7-Zip, and FileZilla.50
S1158 DUSTPAN DUSTPAN is often disguised as a legitimate Windows binary such as w3wp.exe or conn.exe.51
G1006 Earth Lusca Earth Lusca used the command move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service.175
S0605 EKANS EKANS has been disguised as update.exe to appear as a valid executable.147
S0081 Elise If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network.16
G1003 Ember Bear Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to java in victim environments.206
S0171 Felismus Felismus has masqueraded as legitimate Adobe Content Management System files.27
G0137 Ferocious Kitten Ferocious Kitten has named malicious files update.exe and loaded them into the compromise host’s “Public” folder.107
G1016 FIN13 FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war.219
G0046 FIN7 FIN7 has attempted to run Darkside ransomware with the filename sleep.exe.165 Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name.164
S0182 FinFisher FinFisher renames one of its .dll files to uxtheme.dll in an apparent attempt to masquerade as a legitimate file.117116
S0661 FoggyWeb FoggyWeb can be disguised as a Visual Studio file such as Windows.Data.TimeZones.zh-PH.pri to evade detection. Also, FoggyWeb’s loader can mimic a genuine dll file that carries out the same import functions as the legitimate Windows version.dll file.101
G0117 Fox Kitten Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate.215
S0410 Fysbis Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier.132
G0047 Gamaredon Group Gamaredon Group has used legitimate process names to hide malware including svchosst.152 Additionally, Gamaredon Group disguised malicious ZIP archives as Office documents that are related to the invasion.153
S0666 Gelsemium Gelsemium has named malicious binaries serv.exe, winprint.dll, and chrome_elf.dll and has set its persistence in the Registry with the key value Chrome Update to appear legitimate.144
S1197 GoBear GoBear is installed through droppers masquerading as legitimate, signed software installers.53
S0493 GoldenSpy GoldenSpy’s setup file installs initial executables under the folder %WinDir%\System32\PluginManager.66
S0588 GoldMax GoldMax has used filenames that matched the system name, and appeared as a scheduled task impersonating systems management software within the corresponding ProgramData subfolder.36113
S0477 Goopy Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe.136
S0531 Grandoreiro Grandoreiro has named malicious browser extensions and update files to appear legitimate.2930
S0690 Green Lambert Green Lambert has been disguised as a Growl help file.130131
S0697 HermeticWiper HermeticWiper has used the name postgressql.exe to mask a malicious payload.39
S0698 HermeticWizard HermeticWizard has been named exec_32.dll to mimic a legitimate MS Outlook .dll.39
S1249 HexEval Loader HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects.105106
C0038 HomeLand Justice During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.231232
S0070 HTTPBrowser HTTPBrowser’s installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL.60
S1022 IceApple IceApple .NET assemblies have used App_Web_ in their file names to appear legitimate.26
S0483 IcedID IcedID has modified legitimate .dll files to include malicious code.46
G1032 INC Ransom INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.193192
G0119 Indrik Spider Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors.163
S0259 InnaputRAT InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe.121
S0260 InvisiMole InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder.148149
S0015 Ixeshe Ixeshe has used registry values and file names associated with Adobe software, such as AcroRd32.exe.138
S1203 J-magic J-magic can rename itself as “[nfsiod 0]” to masquerade as the local Network File System (NFS) asynchronous I/O server.22
C0050 J-magic Campaign During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service.22
G0004 Ke3chang Ke3chang has dropped their malware into legitimate installed software paths including: C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe, C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe, C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe, and C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe.186
S0526 KGH_SPY KGH_SPY has masqueraded as a legitimate Windows tool.47
G0094 Kimsuky Kimsuky has renamed malware to legitimate names such as ESTCommon.dll or patch.dll.211 Kimsuky has also disguised payloads using legitimate file names including a PowerShell payload named chrome.ps1. 210
S0669 KOCTOPUS KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries.108
S0356 KONNI KONNI has created a shortcut called “Anti virus service.lnk” in an apparent attempt to masquerade as a legitimate file.145
S1160 Latrodectus Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS.88
G0032 Lazarus Group Lazarus Group has renamed malicious code to disguise it as Microsoft’s narrator and other legitimate files.80199
S0395 LightNeuron LightNeuron has used filenames associated with Exchange and Outlook for binary and configuration files, such as winmail.dat.63
S0582 LookBack LookBack has a C2 proxy tool that masquerades as GUP.exe, which is software used by Notepad++.65
G1014 LuminousMoth LuminousMoth has disguised their exfiltration malware as ZoomVideoApp.exe.194
S0409 Machete Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables.7172
G0095 Machete Machete’s Machete MSI installer has masqueraded as a legitimate Adobe Acrobat Reader installer.197
G0059 Magic Hound Magic Hound has used dllhost.exe to mask Fast Reverse Proxy (FRP) and MicrosoftOutLookUpdater.exe for Plink.189188190
S1182 MagicRAT MagicRAT stores configuration data in files and file paths mimicking legitimate operating system resources.35
S0652 MarkiRAT MarkiRAT can masquerade as update.exe and svehost.exe; it has also mimicked legitimate Telegram and Chrome files.107
S0500 MCMD MCMD has been named Readme.txt to appear legitimate.8
S0459 MechaFlounder MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file.12
G0045 menuPass menuPass has been seen changing malicious files to appear legitimate.205
S0455 Metamorfo Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example.126127
S0084 Mis-Type Mis-Type saves itself as a file named msdtc.exe, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.910
S0083 Misdat Misdat saves itself as a file named msdtc.exe, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.910
G0069 MuddyWater MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender.167168169
G0129 Mustang Panda Mustang Panda has used names like adobeupdate.dat and PotPlayerDB.dat to disguise PlugX, and a file named OneDrive.exe to load a Cobalt Strike payload.218 Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe.61
G1020 Mustard Tempest Mustard Tempest has used the filename AutoUpdater.js to mimic legitimate update files and has also used the Cyrillic homoglyph characters С (0xd0a1) and а (0xd0b0), to produce the filename Сhrome.Updаte.zip.16668
G0019 Naikon Naikon has disguised malicious programs as Google Chrome, Adobe, and VMware executables.11
S0630 Nebulae Nebulae uses functions named StartUserModeBrowserInjection and StopUserModeBrowserInjection indicating that it’s trying to imitate chrome_frame_helper.dll.11
S0198 NETWIRE NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder.102
S1090 NightClub NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper.25
S1100 Ninja Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll.32
S0353 NOKKI NOKKI is written to %LOCALAPPDATA%\MicroSoft Updatea\svServiceUpdate.exe prior being executed in a new process in an apparent attempt to masquerade as a legitimate folder and file.62
S0340 Octopus Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger.5758
G0049 OilRig OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe.196
S0138 OLDBAIT OLDBAIT installs itself in %ALLUSERPROFILE%\Application Data\Microsoft\MediaPlayer\updatewindws.exe; the directory name is missing a space and the file name is missing the letter “o.”34
C0012 Operation CuckooBees During Operation CuckooBees, the threat actors renamed a malicious executable to rundll32.exe to allow it to blend in with other Windows system files.228
C0006 Operation Honeybee During Operation Honeybee, the threat actors used a legitimate Windows executable and secure directory for their payloads to bypass UAC.234
C0013 Operation Sharpshooter During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as mssync.exe.235
C0014 Operation Wocao During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs.233
S0402 OSX/Shlayer OSX/Shlayer can masquerade as a Flash Player update.9697
S1017 OutSteel OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: %TEMP%\svjhost.exe.142
S0072 OwaAuth OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\Auth\; the malicious file by the same name is saved in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\bin\.17
G0040 Patchwork Patchwork installed its payload in the startup programs folder as “Baidu Software Update.” The group also adds its second stage payload to the startup programs as “Net Monitor.”171 They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.172
S1050 PcShare PcShare has been named wuauclt.exe to appear as the legitimate Windows Update AutoUpdate Client.5
S0587 Penquin Penquin has mimicked the Cron binary to hide itself on compromised systems.64
S0501 PipeMon PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor.141
S0013 PlugX PlugX has been disguised as legitimate Adobe and PotPlayer files.93 PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs.91929495
G0033 Poseidon Group Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense.213
S1046 PowGoop PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file.123
G0056 PROMETHIUM PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers.143191
S1228 PUBLOAD PUBLOAD has renamed malicious files to mimic legitimate file names such as adobe_wf.exe.13
S0196 PUNCHBUGGY PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%.5556
S1032 PyDCrypt PyDCrypt has dropped DCSrv under the svchost.exe name to disk.37
S0583 Pysa Pysa has executed a malicious executable by naming it svchost.exe.128
S0269 QUADAGENT QUADAGENT used the PowerShell filenames Office365DCOMCheck.ps1 and SystemDiskClean.ps1.85
S1084 QUIETEXIT QUIETEXIT has attempted to change its name to cron upon startup. During incident response, QUIETEXIT samples have been identified that were renamed to blend in with other legitimate files.150
S0565 Raindrop Raindrop was installed under names that resembled legitimate Windows file and directory names.4445
S0629 RainyDay RainyDay has used names to mimic legitimate software including “vmtoolsd.exe” to spoof Vmtools.11
S0458 Ramsay Ramsay has masqueraded as a 7zip installer.8687
S0495 RDAT RDAT has masqueraded as VMware.exe.40
G1039 RedCurl RedCurl mimicked legitimate file names and scheduled tasks, e.g. MicrosoftCurrentupdatesCheck and
MdMMaintenenceTask to mask malicious files and scheduled tasks.178179
C0056 RedPenguin During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd.230
S0125 Remsec The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims.4241
S0496 REvil REvil can mimic the names of known executables.28
G0106 Rocke Rocke has used shell scripts which download mining executables and saves them with the filename “java”.222
S1078 RotaJakiro RotaJakiro has used the filename systemd-daemon in an attempt to appear legitimate.119
S0446 Ryuk Ryuk has constructed legitimate appearing installation folder paths by calling GetWindowsDirectoryW and then inserting a null byte at the fourth character of the path. For Windows Vista or higher, the path would appear as C:\Users\Public.59
S0085 S-Type S-Type may save itself as a file named msdtc.exe, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.910
S1018 Saint Bot Saint Bot has been disguised as a legitimate executable, including as Windows SDK.118
S1099 Samurai Samurai has created the directory %COMMONPROGRAMFILES%\Microsoft Shared\wmi\ to contain DLLs for loading successive stages.125
G0034 Sandworm Team Sandworm Team has avoided detection by naming a malicious binary explorer.exe.220221
S1019 Shark Shark binaries have been named audioddg.pdb and Winlangdb.pdb in order to appear legitimate.19
S0445 ShimRatReporter ShimRatReporter spoofed itself as AlphaZawgyl_font.exe, a specialized Unicode font.7
S0589 Sibot Sibot has downloaded a DLL to the C:\windows\system32\drivers\ folder and renamed it with a .sys extension.36
G1008 SideCopy SideCopy has used a legitimate DLL file name, Duser.dll to disguise a malicious remote access tool.216
G0121 Sidewinder Sidewinder has named malicious files rekeywiz.exe to match the name of a legitimate Windows executable.204
G0091 Silence Silence has named its backdoor “WINWORD.exe”.214
S0468 Skidmap Skidmap has created a fake rm binary to replace the legitimate Linux binary.31
S0533 SLOTHFULMEDIA SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe.15
S1035 Small Sieve Small Sieve can use variations of Microsoft and Outlook spellings, such as “Microsift”, in its file names to avoid detection.69
S1124 SocGholish SocGholish has been named AutoUpdater.js to mimic legitimate update files.68
C0024 SolarWinds Compromise During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign.225226
G0054 Sowbug Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory CSIDL_APPDATA\microsoft\security.98
S0058 SslMM To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.115
S0188 Starloader Starloader has masqueraded as legitimate software update packages such as Adobe Acrobat Reader and Intel.98
S1238 STATICPLUGIN STATICPLUGIN has leveraged naming conventions that match legitimate services to include AdobePlugins.exe.61
G1046 Storm-1811 Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package.162
S1183 StrelaStealer StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company.100
S1034 StrifeWater StrifeWater has been named calc.exe to appear as a legitimate calculator program.84
S0491 StrongPity StrongPity has been bundled with legitimate software installation files for disguise.143
S1042 SUGARDUMP SUGARDUMP has been named CrashReporter.exe to appear as a legitimate Mozilla executable.54
S0559 SUNBURST SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities.45
S0562 SUNSPOT SUNSPOT was identified on disk with a filename of taskhostsvc.exe and it created an encrypted log file at C:\Windows\Temp\vmware-vmdmp.log.112
S0578 SUPERNOVA SUPERNOVA has masqueraded as a legitimate SolarWinds DLL.8990
G1018 TA2541 TA2541 has used file names to mimic legitimate Windows files or system functionality.158
S0586 TAINTEDSCRIBE The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator.80
S1011 Tarrask Tarrask has masqueraded as executable files such as winupdate.exe, date.exe, or win.exe.33
G0139 TeamTNT TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software.151
S0560 TEARDROP TEARDROP files had names that resembled legitimate Window file and directory names.10945
S0595 ThiefQuest ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable.7576
S0665 ThreatNeedle ThreatNeedle chooses its payload creation path from a randomly selected service name from netsvc.120
S0668 TinyTurla TinyTurla has been deployed as w64time.dll to appear legitimate.21
G1022 ToddyCat ToddyCat has used the name debug.exe for malware components.125
S1239 TONESHELL TONESHELL has renamed malicious files to mimic legitimate file names and file extensions.13 TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll.14
S1201 TRANSLATEXT TRANSLATEXT has been named GoogleTranslate.crx to masquerade as a legitimate Chrome extension.103
G0134 Transparent Tribe Transparent Tribe can mimic legitimate Windows directories by using the same icons and names.173
C0030 Triton Safety Instrumented System Attack In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.
S1196 Troll Stealer Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file.5253
G0081 Tropic Trooper Tropic Trooper has hidden payloads in Flash directories and fake installer files.187
G0010 Turla Turla has named components of LunarWeb to mimic Zabbix agent logs.217
S0386 Ursnif Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names.70
S0136 USBStealer USBStealer mimics a legitimate Russian program called USB Disk Security.104
G1047 Velvet Ant Velvet Ant used a malicious DLL, iviewers.dll, that mimics the legitimate “OLE/COM Object Viewer” within Windows.209
S1217 VIRTUALPITA VIRTUALPITA samples have been found in /usr/libexec/setconf/ksmd and /usr/bin/ksmd, named to spoof the legitimate Kernel Same-Page Merging Daemon binary. 110
G1017 Volt Typhoon Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.156155154
G0107 Whitefly Whitefly has named the malicious DLL the same name as DLLs belonging to legitimate software from various security vendors.195
S0141 Winnti for Windows A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name.134
G0090 WIRTE WIRTE has named a first stage dropper Kaspersky Update Agent in order to appear legitimate.170
S1248 XORIndex Loader XORIndex Loader has leveraged legitimate package names to mimic frequently utilized tools to entice victims to download and execute malicious payloads.135
S0086 ZLib ZLib mimics the resource version information of legitimate Realtek Semiconductor, Nvidia, or Synaptics modules.9

Mitigations

ID Mitigation Description
M1045 Code Signing Require signed binaries and images.
M1038 Execution Prevention Use tools that restrict program execution via application control by attributes other than file name for common operating system utilities that are needed.
M1022 Restrict File and Directory Permissions Use file system access controls to protect folders such as C:\Windows\System32.

References


  1. Carr, N.. (2018, October 25). Nick Carr Status Update Masquerading. Retrieved September 12, 2024. 

  2. Docker. (n.d.). Docker Images. Retrieved April 6, 2021. 

  3. Ewing, P. (2016, October 31). How to Hunt: The Masquerade Ball. Retrieved October 31, 2016. 

  4. Michael Katchinskiy and Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved March 24, 2025. 

  5. Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022. 

  6. Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023. 

  7. Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020. 

  8. Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020. 

  9. Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021. 

  10. Microsoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016. 

  11. Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021. 

  12. Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020. 

  13. Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025. 

  14. Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025. 

  15. DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020. 

  16. Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016. 

  17. Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018. 

  18. Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020. 

  19. ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022. 

  20. Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021. 

  21. Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025. 

  22. Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024. 

  23. Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020. 

  24. Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023. 

  25. CrowdStrike. (2022, May). ICEAPPLE: A NOVEL INTERNET INFORMATION SERVICES (IIS) POST-EXPLOITATION FRAMEWORK. Retrieved June 27, 2022. 

  26. Julia Kisielius. (2017, April 25). The Felismus RAT: Powerful Threat, Mysterious Purpose. Retrieved November 17, 2024. 

  27. Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020. 

  28. Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020. 

  29. ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020. 

  30. Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020. 

  31. Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024. 

  32. Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022. 

  33. FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015. 

  34. Asheer Malhotra, Vitor Ventura & Jungsoo An, Cisco Talos. (2022, September 7). MagicRAT: Lazarus’ latest gateway into victim networks. Retrieved December 30, 2024. 

  35. Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021. 

  36. Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022. 

  37. US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020. 

  38. ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022. 

  39. Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020. 

  40. Kaspersky Lab’s Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Retrieved August 17, 2016. 

  41. Warwick Ashford. (2016, August 8). Strider cyber attack group deploying malware for espionage. Retrieved January 10, 2024. 

  42. Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023. 

  43. Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021. 

  44. MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021. 

  45. Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024. 

  46. Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020. 

  47. M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021. 

  48. Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021. 

  49. Hod Gavriel. (2019, November 21). Dtrack: In-depth analysis of APT on a nuclear power plant. Retrieved January 20, 2021. 

  50. Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024. 

  51. Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025. 

  52. Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025. 

  53. Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022. 

  54. Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018. 

  55. Gorelik, M.. (2019, June 10). SECURITY ALERT: FIN8 IS BACK IN BUSINESS, TARGETING THE HOSPITALITY INDUSTRY. Retrieved June 13, 2019. 

  56. Kaspersky Lab’s Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018. 

  57. Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021. 

  58. Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020. 

  59. Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016. 

  60. Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025. 

  61. Grunzweig, J., Lee, B. (2018, September 27). New KONNI Malware attacking Eurasia and Southeast Asia. Retrieved November 5, 2018. 

  62. Faou, M. (2019, May). Turla LightNeuron: One email away from remote code execution. Retrieved June 24, 2019. 

  63. Leonardo. (2020, May 29). MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64”. Retrieved March 11, 2021. 

  64. Raggi, M. Schwarz, D.. (2019, August 1). LookBack Malware Targets the United States Utilities Sector with Phishing Attacks Impersonating Engineering Licensing Boards. Retrieved February 25, 2021. 

  65. Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020. 

  66. Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021. 

  67. Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024. 

  68. NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022. 

  69. Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019. 

  70. ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019. 

  71. Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019. 

  72. Kohler, A. and Lopez, C. (2024, April 30). Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware. Retrieved August 20, 2024. 

  73. Stokes, P. (2024, May 9). macOS Cuckoo Stealer | Ensuring Detection and Defense as New Samples Rapidly Emerge. Retrieved August 20, 2024. 

  74. Patrick Wardle. (2020, July 3). OSX.EvilQuest Uncovered part ii: insidious capabilities. Retrieved March 21, 2021. 

  75. Thomas Reed. (2020, July 7). Mac ThiefQuest malware may not be ransomware after all. Retrieved March 22, 2021. 

  76. Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020. 

  77. Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020. 

  78. Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021. 

  79. USG. (2020, May 12). MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE. Retrieved March 5, 2021. 

  80. ClearSky Research Team. (2020, August 13). Operation ‘Dream Job’ Widespread North Korean Espionage Campaign. Retrieved December 20, 2021. 

  81. Salem, A. (2022, April 27). The chronicles of Bumblebee: The Hook, the Bee, and the Trickbot connection. Retrieved September 2, 2022. 

  82. Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025. 

  83. Cybereason Nocturnus. (2022, February 1). StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations. Retrieved August 15, 2022. 

  84. Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018. 

  85. Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020. 

  86. Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel’s infiltration and isolation network. Retrieved March 24, 2021. 

  87. Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024. 

  88. Riley, W. (2020, December 1). SUPERNOVA SolarWinds .NET Webshell Analysis. Retrieved February 18, 2021. 

  89. Tennis, M. (2020, December 17). SUPERNOVA: A Novel .NET Webshell. Retrieved February 22, 2021. 

  90. Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025. 

  91. EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025. 

  92. Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022. 

  93. Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025. 

  94. Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025. 

  95. Carbon Black Threat Analysis Unit. (2019, February 12). New macOS Malware Variant of Shlayer (OSX) Discovered. Retrieved August 8, 2019. 

  96. Long, Joshua. (2018, February 21). OSX/Shlayer: New Mac malware comes out of its shell. Retrieved August 28, 2019. 

  97. Symantec Security Response. (2017, November 7). Sowbug: Cyber espionage group targets South American and Southeast Asian governments. Retrieved November 16, 2017. 

  98. Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021. 

  99. Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024. 

  100. Ramin Nafisi. (2021, September 27). FoggyWeb: Targeted NOBELIUM malware leads to persistent backdoor. Retrieved October 4, 2021. 

  101. Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021. 

  102. Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024. 

  103. Calvet, J. (2014, November 11). Sednit Espionage Group Attacking Air-Gapped Networks. Retrieved January 4, 2017. 

  104. Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025. 

  105. Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025. 

  106. GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021. 

  107. Ionut Arghire. (2021, February 24). New ‘LazyScripter’ Hacking Group Targets Airlines. Retrieved January 10, 2024. 

  108. FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021. 

  109. Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025. 

  110. Fishbein, N., Kajiloti, M.. (2020, July 28). Watch Your Containers: Doki Infecting Docker Servers in the Cloud. Retrieved March 30, 2021. 

  111. CrowdStrike Intelligence Team. (2021, January 11). SUNSPOT: An Implant in the Build Process. Retrieved January 11, 2021. 

  112. CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022. 

  113. Levene, B. et al.. (2018, March 7). Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent. Retrieved March 31, 2018. 

  114. Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019. 

  115. Allievi, A.,Flori, E. (2018, March 01). FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines. Retrieved July 9, 2018. 

  116. FinFisher. (n.d.). Retrieved September 12, 2024. 

  117. Hasherezade. (2021, April 6). A deep dive into Saint Bot, a new downloader. Retrieved June 9, 2022. 

  118. Alex Turing. (2021, May 6). RotaJakiro, the Linux version of the OceanLotus. Retrieved June 14, 2023. 

  119. Vyacheslav Kopeytsev and Seongsu Park. (2021, February 25). Lazarus targets defense industry with ThreatNeedle. Retrieved October 27, 2021. 

  120. ASERT Team. (2018, April 04). Innaput Actors Utilize Remote Access Trojan Since 2016, Presumably Targeting Victim Files. Retrieved July 9, 2018. 

  121. Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018. 

  122. FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022. 

  123. DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018. 

  124. Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024. 

  125. Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020. 

  126. ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021. 

  127. CERT-FR. (2020, April 1). ATTACKS INVOLVING THE MESPINOZA/PYSA RANSOMWARE. Retrieved March 1, 2021. 

  128. Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023. 

  129. Sandvik, Runa. (2021, October 1). Made In America: Green Lambert for OS X. Retrieved March 21, 2022. 

  130. Sandvik, Runa. (2021, October 18). Green Lambert and ATT&CK. Retrieved November 17, 2024. 

  131. Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017. 

  132. PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017. 

  133. Cap, P., et al. (2017, January 25). Detecting threat actors in recent German industrial attacks with Windows Defender ATP. Retrieved February 8, 2017. 

  134. Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025. 

  135. Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018. 

  136. Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022. 

  137. Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019. 

  138. Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020. 

  139. Roccio, T., et al. (2021, April). Technical Analysis of Cuba Ransomware. Retrieved June 18, 2021. 

  140. Tartare, M. et al. (2020, May 21). No “Game over” for the Winnti Group. Retrieved August 24, 2020. 

  141. Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022. 

  142. Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020. 

  143. Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021. 

  144. Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018. 

  145. TrendMicro. (2014, September 03). DARKCOMET. Retrieved November 6, 2018. 

  146. Dragos. (2020, February 3). EKANS Ransomware and ICS Operations. Retrieved February 9, 2021. 

  147. Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018. 

  148. Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020. 

  149. Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023. 

  150. Darin Smith. (2022, April 21). TeamTNT targeting AWS, Alibaba. Retrieved August 4, 2022. 

  151. Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022. 

  152. Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025. 

  153. CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024. 

  154. Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023. 

  155. NSA et al. (2023, May 24). People’s Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023. 

  156. Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018. 

  157. Larson, S. and Wise, J. (2022, February 15). Charting TA2541’s Flight. Retrieved September 12, 2023. 

  158. Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019. 

  159. Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021. 

  160. Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024. 

  161. Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025. 

  162. Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021. 

  163. The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025. 

  164. Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021. 

  165. Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024. 

  166. Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018. 

  167. Adamitis, D. et al. (2019, May 20). Recent MuddyWater-associated BlackWater campaign shows signs of new anti-detection techniques. Retrieved June 5, 2019. 

  168. Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021. 

  169. Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022. 

  170. Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024. 

  171. Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018. 

  172. Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021. 

  173. FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015. 

  174. Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022. 

  175. Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021 

  176. Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024. 

  177. Group-IB. (2020, August). RedCurl: The Pentest You Didn’t Know About. Retrieved August 9, 2024. 

  178. Group-IB. (2021, November). RedCurl: The Awakening. Retrieved August 14, 2024. 

  179. Douglas Bienstock. (2022, August 18). You Can’t Audit Me: APT29 Continues Targeting Microsoft 365. Retrieved February 23, 2023. 

  180. Guerrero-Saade, J. (2021, June 1). NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks. Retrieved August 4, 2021. 

  181. NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021. 

  182. Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020.. 

  183. CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024. 

  184. Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020. 

  185. MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022. 

  186. Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020. 

  187. DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023. 

  188. DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022. 

  189. Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020. 

  190. SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024. 

  191. Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024. 

  192. Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022. 

  193. Symantec. (2019, March 6). Whitefly: Espionage Group has Singapore in Its Sights. Retrieved May 26, 2020. 

  194. Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024. 

  195. kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020. 

  196. Kaspersky Lab’s Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018. 

  197. Pradhan, A. (2022, February 8). LolZarus: Lazarus Group Incorporating Lolbins into Campaigns. Retrieved March 22, 2022. 

  198. Microsoft. (2016, June 9). Reverse-engineering DUBNIUM. Retrieved March 31, 2021. 

  199. Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016. 

  200. Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016. 

  201. Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020. 

  202. Rewterz. (2020, June 22). Analysis on Sidewinder APT Group – COVID-19. Retrieved January 29, 2021. 

  203. US District Court Southern District of New York. (2018, December 17). United States v. Zhu Hua Indictment. Retrieved December 17, 2020. 

  204. US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024. 

  205. FBI. (2020, September 17). Indicators of Compromise Associated with Rana Intelligence Computing, also known as Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, and ITG07. Retrieved December 10, 2020. 

  206. Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020. 

  207. Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025. 

  208. Den Iuzvyk, Tim Peck. (2025, February 13). Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks. Retrieved August 19, 2025. 

  209. Hossein Jazi. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved January 10, 2024. 

  210. Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024. 

  211. Kaspersky Lab’s Global Research and Analysis Team. (2016, February 9). Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionage. Retrieved March 16, 2016. 

  212. Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020. 

  213. CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020. 

  214. Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022. 

  215. Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024. 

  216. Insikt Group. (2020, July 28). CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS. Retrieved April 13, 2021. 

  217. Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023. 

  218. Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020. 

  219. Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020. 

  220. Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020. 

  221. Dragos Inc.. (2017, June 13). CRASHOVERRIDE Analysis of the Threat to Electric Grid Operations. Retrieved December 18, 2020. 

  222. Venere, G. Neal, C. (2022, June 21). Avos ransomware group expands with new attack arsenal. Retrieved January 11, 2023. 

  223. Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020. 

  224. MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021. 

  225. Miller, S, et al. (2019, April 10). TRITON Actor TTP Profile, Custom Attack Tools, Detections, and ATT&CK Mapping. Retrieved April 16, 2019. 

  226. Cybereason Nocturnus. (2022, May 4). Operation CuckooBees: Deep-Dive into Stealthy Winnti Techniques. Retrieved September 22, 2022. 

  227. Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022. 

  228. Lamparski, L. et al. (2025, March 11). Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers. Retrieved June 24, 2025. 

  229. CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024. 

  230. Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024. 

  231. Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020. 

  232. Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018. 

  233. Sherstobitoff, R., Malhotra, A., et. al.. (2018, December 18). Operation Sharpshooter Campaign Targets Global Defense, Critical Infrastructure. Retrieved May 14, 2020.