MITRE ATT&CK Technique
T1036Masquerading
- First Reported
- Sep 26, 2026
- Latest Reported
- Sep 26, 2026
Official Description
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Renaming abusable system utilities to evade security monitoring is also a form of [Masquerading](https://attack.mitre.org/techniques/T1036).(Citation: LOLBAS Main Site)
Renaming abusable system utilities to evade security monitoring is also a form of [Masquerading](https://attack.mitre.org/techniques/T1036).(Citation: LOLBAS Main Site)
- Tactics
- Stealth
- Platforms
- Containers, ESXi, Linux, macOS, Windows
- MITRE Version
- 2.0
- Last Modified
- May 12, 2026
Sub-techniques (12)
T1036.001 · Invalid Code SignatureT1036.002 · Right-to-Left OverrideT1036.003 · Rename Legitimate UtilitiesT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1036.006 · Space after FilenameT1036.007 · Double File ExtensionT1036.008 · Masquerade File TypeT1036.009 · Break Process TreesT1036.010 · Masquerade Account Name
Reported Context (1)
- Ple64.exe masqueraded as a signed Light Alloy media-player installer while loading the SIDEEYE backdoor. ShinyHunters Resume Mass Exploitation of Oracle PeopleSoft Vulnerability CVE-2026-35273
CVE (1)
Malware (1)
Threat Actors (2)
MITRE ATT&CK (10)
Vendors (3)
Products (3)
Tools (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.