Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1001/T1001.003
MITRE ATT&CK Sub-Technique

T1001.003: Protocol or Service Impersonation

ShareXLinkedInRedditHN

Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic. Adversaries may impersonate a fake SSL/TLS handshake to make it look like subsequent traffic is SSL/TLS encrypted, potentially interfering with some security tooling, or to make the traffic look like it is related with a trusted entity. Adversaries may also leverage legitimate protocols to impersonate expected web traffic or trusted services. For example, adversaries may manipulate HTTP headers, URI endpoints, SSL certificates, and transmitted data to disguise C2 communications or mimic legitimate services such as Gmail, Google Drive, and Yahoo Messenger.(Citation: ESET Okrum July 2019)(Citation: Malleable-C2-U42)

Tactics
Command and Control
Platforms
ESXi, Linux, macOS, Windows

▪Parent technique

T1001: Data Obfuscation

▪Mitigations (1)

M1031Network Intrusion Prevention

Use intrusion detection signatures to block traffic at network boundaries.

▪Used by groups (3)

G0032Lazarus GroupG0126HigaisaG0129Mustang Panda

▪Software using this technique (18)

S0022UroburosmalwareS0076FakeMmalwareS0154Cobalt StrikemalwareS0181FALLCHILLmalwareS0239BankshotmalwareS0245BADCALLmalwareS0246HARDRAINmalwareS0260InvisiMolemalwareS0387KeyBoymalwareS0439OkrummalwareS0559SUNBURSTmalwareS0586TAINTEDSCRIBEmalwareS1100NinjamalwareS1120FRAMESTINGmalwareS1226BOOKWORMmalwareS1227StarProxymalwareS1228PUBLOADmalwareS1239TONESHELLmalware

▪Reference

T1001.003on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.