T1036.004: T1036.004
Essential information
- MITRE technique ID
T1036.004- Confidence
- 100/100
- Revoked
- No
- Published
- 10/02/2020 21:30
- Modified
- 27/03/2026 01:10
- Author / Source
- The MITRE Corporation
Aliases
Masquerade Task or Service
Platforms
windows macos linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (54)
-
RansomHub usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Earth Estries usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Silver Fox usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Aquatic Panda usesThe MITRE Corporation Confidence 100
[Aquatic Panda](https://attack.mitre.org/groups/G0143) is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, [Aquatic Panda](https://attack.mitre.org/groups/G0143) has primarily…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active…
First seen 01/01/1970 · Last seen 16/11/5138 · -
EvilConwi usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Wizard Spider](https://attack.mitre.org/groups/G0102) is a Russia-based financially motivated threat group originally known for the creation and deployment of [TrickBot](https://attack.mitre.org/software/S0266) since at least 2016. [Wizard Spider](https://attack.mitre.org/groups/G0102) possesses a diverse arsenal…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Earth Baxia usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Silver Dragon usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (74)
-
COMPOOD usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Maze usesFamily The MITRE Corporation Confidence 100
[Maze](https://attack.mitre.org/software/S0449) ransomware, previously known as "ChaCha", was discovered in May 2019. In addition to encrypting files on victim machines for impact, [Maze](https://attack.mitre.org/software/S0449) operators conduct information stealing campaigns prior…
First seen 01/01/1970 · Last seen 16/11/5138 · -
XMRig usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Kwampirs usesFamily The MITRE Corporation Confidence 100
[Kwampirs](https://attack.mitre.org/software/S0236) is a backdoor Trojan used by [Orangeworm](https://attack.mitre.org/groups/G0071). [Kwampirs](https://attack.mitre.org/software/S0236) has been found on machines which had software installed for the use and control of high-tech imaging devices such…
First seen 01/01/1970 · Last seen 16/11/5138 · -
WeaselStore usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Exaramel for Windows usesFamily The MITRE Corporation Confidence 100
[Exaramel for Windows](https://attack.mitre.org/software/S0343) is a backdoor used for targeting Windows systems. The Linux version is tracked separately under [Exaramel for Linux](https://attack.mitre.org/software/S0401).(Citation: ESET TeleBots Oct 2018)
First seen 01/01/1970 · Last seen 16/11/5138 · -
cd00r usesFamily The MITRE Corporation Confidence 100
[cd00r](https://attack.mitre.org/software/S1204) is an open-source backdoor for UNIX and UNIX-variant operating systems that was orginally released in 2000. [cd00r](https://attack.mitre.org/software/S1204) source code is primarily based on a packet-capturing program as…
First seen 01/01/1970 · Last seen 16/11/5138 · -
ShellcodeRunner usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AnubisBackdoor usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SilverScreen usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Mirai usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
win_sys.exe usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (50)
-
11 MITREs 2 Malwares 6 Observables 1 APT
-
1 CVE 14 MITREs 2 Malwares 10 Observables 1 APT
-
1 CVE 11 MITREs 5 Malwares 13 Observables
-
16 MITREs 6 Observables
-
8 MITREs 1 Malware 9 Observables 1 APT
-
5 CVEs 17 MITREs 6 Malwares 7 Observables
-
9 MITREs 1 Malware 37 Observables 1 APT
-
3 CVEs 20 MITREs 4 Malwares 36 Observables
-
2 CVEs 18 MITREs 2 Malwares 38 Observables
-
2 CVEs 14 MITREs 3 Malwares 9 Observables 1 APT
-
16 MITREs 9 Malwares 90 Observables 1 APT
-
20 MITREs 2 Malwares 11 Observables 1 APT
Vulnerabilities (CVE) (65)
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use …
- Attack vector
- NETWORK
- Published
- 29/01/2021
- Modified
- 15/07/2026
The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the …
- Attack vector
- Network
- Complexity
- Low
- EPSS
- 0.0002 (P4.5%)
- Published
- 11/05/2026
- Modified
- 13/07/2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath …
- Attack vector
- Network
- Published
- 15/07/2024
- Modified
- 21/12/2025
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, …
- Published
- 10/05/2022
- Modified
- 20/12/2025
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code …
- Published
- 03/11/2021
- Modified
- 20/12/2025
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a …
- Attack vector
- NETWORK
- Published
- 07/01/2026
- Modified
- 09/03/2026
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to …
- Attack vector
- NETWORK
- Published
- 27/04/2021
- Modified
- 13/07/2026
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked …
- Attack vector
- NETWORK
- Published
- 24/07/2025
- Modified
- 13/07/2026
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on …
- Published
- 24/06/2025
- Modified
- 20/03/2026
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to …
- Attack vector
- Network
- Published
- 14/08/2025
- Modified
- 27/05/2026
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware …
- Attack vector
- Network
- Published
- 20/07/2025
- Modified
- 21/12/2025
Tool (2)
-
CSPY Downloader usesThe MITRE Corporation Confidence 100
[CSPY Downloader](https://attack.mitre.org/software/S0527) is a tool designed to evade analysis and download additional payloads used by [Kimsuky](https://attack.mitre.org/groups/G0094).(Citation: Cybereason Kimsuky November 2020)
-
IronNetInjector usesThe MITRE Corporation Confidence 100
[IronNetInjector](https://attack.mitre.org/software/S0581) is a [Turla](https://attack.mitre.org/groups/G0010) toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including [ComRAT](https://attack.mitre.org/software/S0126).(Citation: Unit…
Campaign (1)
-
KV Botnet Activity uses