T1036.005Match Legitimate Resource Name or Location
T1036.005 — Match Legitimate Resource Name or Location is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 61 detection use cases covering it and 41 threat-intel articles citing it.
Defense Evasion
61Use cases
41Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1036 · Masquerading
Use cases covering this technique (61)
Attacker Tools On Endpoint Windows LOLBAS Executed Outside Expected Path Windows MSC EvilTwin Directory Path Manipulation Windows Process Execution From ProgramData Windows Process Execution in Temp Dir Windows Suspicious Process File Path [LLM] VMware-impersonating cron jobs drop JSP webshell (vmware-perf-update.jsp) [LLM] HoneyMyte DLL side-load: renamed Sangfor 'defender.exe' loading malicious libngs.dll [LLM] CoolClient injection target: masqueraded 'synchost.exe' (svchost typosquat) execution [LLM] HoneyMyte Defender exclusion for fake 'Microsoft\Windows Defender' path via WMIC MSFT_MpPreference [LLM] CoolClient sideloader staging: xcopy clones legit Windows Defender folder into fake Microsoft\Windows Defender dir [LLM] HoneyMyte DLL side-load: renamed Sangfor defender.exe loads malicious libngs.dll from fake Defender dir [LLM] macOS root LaunchDaemon persistence dropped by untrusted process (Apple crash-reporter impersonation) [LLM] CornFlake RAT persistence via svchost32.exe masquerade in %APPDATA% [LLM] CornFlake C2 egress from masqueraded svchost32.exe in AppData [LLM] Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) [LLM] Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) [LLM] AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ [LLM] SleeperGem privilege escalation: setuid-root shell planted as /usr/local/sbin/ping6 [LLM] Velora macOS backdoor launchctl persistence (com.apple.Terminal.profiler.plist) [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) [LLM] macOS.Gaslight LaunchAgent persistence masquerading as com.apple.system.services.activity [LLM] easy-day-js stealer persistence masquerading as Node tooling (NodePackages / LaunchAgent / systemd) [LLM] SPECTRALVIPER DLL side-load: IntelAudioService.exe (renamed dtlupdate.exe) loads DtlCrashCatch.dll [LLM] Bun runtime download to /tmp from a node process during npm install [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory [LLM] Python backdoor self-daemonisation via __DAEMONIZED=1 spawned by VS Code helper or node [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux [LLM] FrostyNeighbor PicassoLoader drop to %AppData%\WinDataScope\Update.js [LLM] FrostyNeighbor Cobalt Strike beacon ViberPC.dll image load [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding [LLM] whisper.dll loaded / svchost.exe spawned outside services.exe (GopherWhisper JabGopher injection) [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) [LLM] launchctl persistence registering zsh.profiler service from non-admin location [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) [LLM] IoliteLabs Stage-2 regsvr32 LOLbin loading ntuser DLL from fake Chrome\ChromeUpdate path [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) [LLM] Linux user-systemd sysmon persistence drop (~/.config/sysmon/sysmon.py + sysmon.service) [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) [LLM] SlimAgent / BeardShell DLL load with implant filename outside System32 [LLM] PlugX DLL side-load — G DATA Avk.exe running from C:\Users\Public\GDatas\ [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) [LLM] DynoWiper schtask.exe / *_update.exe execution from C:\inetpub\pub\ [LLM] DynoWiper deployment from shared inetpub\pub directory (Sandworm, Poland Dec 2025) [LLM] NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard path [LLM] NosyDoor persistence: scheduled task 'OneDrive Reporting Task-S-1-5-21-' under Microsoft folder [LLM] NosyDoor dropper file artefacts in C:\Windows\Microsoft.NET\Framework [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. [LLM] DaemonicLogistics fake-Tencent payload drop (logo.gif at %PROGRAMDATA%\Tencent\QQUpdateMgr\UpdateFiles) [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect [LLM] Process execution from masquerade directory C:\$Windows.~SXK (Discord/Roblox stealer)Articles citing this technique (41)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55