Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1655/T1655.001
MITRE ATT&CK Sub-Technique

T1655.001: Match Legitimate Name or Location

ShareXLinkedInRedditHN

Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by giving artifacts the name and icon of a legitimate, trusted application (i.e., Settings), or using a package name that matches legitimate, trusted applications (i.e., `com.google.android.gm`). Adversaries may also use the same icon of the file or application they are trying to mimic.

Tactics
Defense Evasion
Platforms
Android, iOS

▪Parent technique

T1655: Masquerading

▪Mitigations (1)

M1011User Guidance

Describes any guidance or training given to users to set particular configuration settings or avoid specific potentially risky behaviors.

▪Used by groups (3)

G0097Bouncing GolfG1019MoustachedBouncerG1028APT-C-23

▪Software using this technique (41)

S0292AndroRATmalwareS0301DendroidmalwareS0314X-Agent for AndroidmalwareS0318XLoader for AndroidmalwareS0320DroidJackmalwareS0418ViceLeakermalwareS0419SimBadmalwareS0422AnubismalwareS0423GinpmalwareS0440Agent SmithmalwareS0478EventBotmalwareS0480CerberusmalwareS0485MandrakemalwareS0489WolfRATmalwareS0506ViperRATmalwareS0509FakeSpymalwareS0522ExobotmalwareS0524AndroidOS/MalLocker.BmalwareS0525Android/AdDisplay.AshasmalwareS0529CarbonStealmalwareS0536GPlayedmalwareS0539Red Alert 2.0malwareS0540AsacubmalwareS0544HenBoxmalwareS0549SilkBeanmalwareS0550DoubleAgentmalwareS0551GoldenEaglemalwareS0555CHEMISTGAMESmalwareS0558Tiktok PromalwareS0577FrozenCellmalwareS1077HornbillmalwareS1079BOULDSPYmalwareS1080FakecallsmalwareS1083ChameleonmalwareS1094BRATAmalwareS1126PhenakitemalwareS1195SpyC23malwareS1214Android/SpyAgentmalwareS1231GodFathermalwareS1243DCHSpymalwareS9005DocSwapmalware

▪Reference

T1655.001on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.