Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1036/T1036.004
MITRE ATT&CK Sub-Technique

T1036.004: Masquerade Task or Service

ShareXLinkedInRedditHN

Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.(Citation: TechNet Schtasks)(Citation: Systemd Service Units) Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones. Tasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Fysbis Dr Web Analysis)

Tactics
Stealth
Platforms
Linux, macOS, Windows

▪Parent technique

T1036: Masquerading

▪Used by groups (23)

G0008CarbanakG0019NaikonG0032Lazarus GroupG0037FIN6G0046FIN7G0050APT32G0056PROMETHIUMG0059Magic HoundG0094KimsukyG0096APT41G0099APT-C-36G0102Wizard SpiderG0117Fox KittenG0126HigaisaG0128ZIRCONIUMG0135BackdoorDiplomacyG0143Aquatic PandaG1002BITTERG1016FIN13G1035Winter VivernG1048UNC3886G1053Storm-0501G1055VOID MANTICORE

▪Software using this technique (62)

S0013PlugXmalwareS0022UroburosmalwareS0118NidiranmalwareS0126ComRATmalwareS0140ShamoonmalwareS0148RTMmalwareS0169RawPOSmalwareS0178TruvasysmalwareS0180VolgmermalwareS0223POWERSTATSmalwareS0236KwampirsmalwareS0259InnaputRATmalwareS0260InvisiMolemalwareS0261CatchamasmalwareS0343Exaramel for WindowsmalwareS0345SeasaltmalwareS0352OSX_OCEANLOTUS.DmalwareS0356KONNImalwareS0367EmotetmalwareS0409MachetemalwareS0410FysbismalwareS0438AttormalwareS0439OkrummalwareS0444ShimRatmalwareS0449MazemalwareS0471build_downermalwareS0491StrongPitymalwareS0495RDATmalwareS0527CSPY DownloadertoolS0533SLOTHFULMEDIAmalwareS0534BazarmalwareS0538CrutchmalwareS0554EgregormalwareS0581IronNetInjectortoolS0588GoldMaxmalwareS0601HildegardmalwareS0607KillDiskmalwareS0629RainyDaymalwareS0630NebulaemalwareS0647TurianmalwareS0663SysUpdatemalwareS0668TinyTurlamalwareS0688MeteormalwareS0690Green LambertmalwareS1011TarraskmalwareS1013ZxxZmalwareS1027Heyoka BackdoormalwareS1031PingPullmalwareS1033DCSrvmalwareS1042SUGARDUMPmalwareS1044FunnyDreammalwareS1052DEADEYEmalwareS1064SVCReadymalwareS1070Black BastamalwareS1090NightClubmalwareS1130Raspberry RobinmalwareS1134DEADWOODmalwareS1140SpicamalwareS1217VIRTUALPITAmalwareS1226BOOKWORMmalwareS1239TONESHELLmalwareS1242Qilinmalware

▪Reference

T1036.004on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.