T1036.005Match Legitimate Resource Name or Location
T1036.005 — Match Legitimate Resource Name or Location is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 73 detection use cases covering it and 52 threat-intel articles citing it.
Defense Evasion
73Use cases
52Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1036 · Masquerading
Use cases covering this technique (73)
Attacker Tools On Endpoint Windows LOLBAS Executed Outside Expected Path Windows MSC EvilTwin Directory Path Manipulation Windows Process Execution From ProgramData Windows Process Execution in Temp Dir Windows Suspicious Process File Path [LLM] Tengu guardian process masquerading as kernel thread [kworker/0:0] [LLM] Operation BlueDash fake Teams/Zoom update payload-host infrastructure contact [LLM] msaRAT: MSI impersonating Windows update executed from ProgramData [LLM] Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) [LLM] Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) [LLM] AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) [LLM] CAV3RN framework module DLLs loaded/dropped (AzureCommunication / n-HTCommp / masqueraded uxtheme) [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ [LLM] SleeperGem privilege escalation: setuid-root shell planted as /usr/local/sbin/ping6 [LLM] pythonw.exe loader executing from deceptive %LocalAppData%\Temp dir (ACR Stealer) [LLM] HelloInjector DLL side-load: wtsapi32.dll dropped into ViPNet Update System dir [LLM] HelloNet renamed-PuTTY reverse SSH tunnel to 5.39.253.206 [LLM] GoSerpent/McMx masquerading proxy binaries lass.exe and updates.exe [LLM] Second-stage sync.js dropped under OS 'NodeJS' masquerade directory [LLM] Velora macOS backdoor launchctl persistence (com.apple.Terminal.profiler.plist) [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) [LLM] TinyRCT backdoor masquerading as PerfWatson2.exe executing from %LOCALAPPDATA% [LLM] SoftEther VPN / VNT tunneler masquerading as VMware vmtools.exe [LLM] Scheduled task persistence for GoogleUpdater or VMware-disguised VNT binary [LLM] macOS.Gaslight LaunchAgent persistence masquerading as com.apple.system.services.activity [LLM] easy-day-js stealer persistence masquerading as Node tooling (NodePackages / LaunchAgent / systemd) [LLM] SPECTRALVIPER DLL side-load: IntelAudioService.exe (renamed dtlupdate.exe) loads DtlCrashCatch.dll [LLM] Bun runtime download to /tmp from a node process during npm install [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory [LLM] Python backdoor self-daemonisation via __DAEMONIZED=1 spawned by VS Code helper or node [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux [LLM] FrostyNeighbor PicassoLoader drop to %AppData%\WinDataScope\Update.js [LLM] FrostyNeighbor Cobalt Strike beacon ViberPC.dll image load [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding [LLM] whisper.dll loaded / svchost.exe spawned outside services.exe (GopherWhisper JabGopher injection) [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) [LLM] launchctl persistence registering zsh.profiler service from non-admin location [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) [LLM] IoliteLabs Stage-2 regsvr32 LOLbin loading ntuser DLL from fake Chrome\ChromeUpdate path [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) [LLM] Linux user-systemd sysmon persistence drop (~/.config/sysmon/sysmon.py + sysmon.service) [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 [LLM] TeamPCP msbuild.exe persistence in user Startup folder [LLM] CanisterWorm persistence: pglog/pg_state/internal-monitor systemd unit and /tmp/pglog drop [LLM] GlassWorm Stage-3a UpdateLedger Run-key persistence pointing at %TEMP%\SKuyzYcDD.exe [LLM] GlassWorm Stage-3a Ledger impersonator binary execution (SHA256 06fab21d / SKuyzYcDD.exe) [LLM] Glassworm side-staged Node.js runtime under %APPDATA%\_node_x86 / _node_x64 [LLM] SlimAgent / BeardShell DLL load with implant filename outside System32 [LLM] PlugX DLL side-load — G DATA Avk.exe running from C:\Users\Public\GDatas\ [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) [LLM] DynoWiper schtask.exe / *_update.exe execution from C:\inetpub\pub\ [LLM] DynoWiper deployment from shared inetpub\pub directory (Sandworm, Poland Dec 2025) [LLM] NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard path [LLM] NosyDoor persistence: scheduled task 'OneDrive Reporting Task-S-1-5-21-' under Microsoft folder [LLM] NosyDoor dropper file artefacts in C:\Windows\Microsoft.NET\Framework [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. [LLM] DaemonicLogistics fake-Tencent payload drop (logo.gif at %PROGRAMDATA%\Tencent\QQUpdateMgr\UpdateFiles) [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) [LLM] Python interpreter executed from %TEMP% / Public — RomCom DLL side-load chain (CVE-2025-8088) [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect [LLM] Process execution from masquerade directory C:\$Windows.~SXK (Discord/Roblox stealer)Articles citing this technique (52)
crit Don’t swing at everything art-106
high GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration art-153