Threadlinqs IntelligenceStart free

ATT&CK techniqueStealth (formerly Defense Evasion)

T1036 Masquerading

Stealth (formerly Defense Evasion)Enterprise

As of 2026-10-05, T1036 (Masquerading) appears in 845 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
845251 critical, 492 high, 94 medium, 5 low
First seen
2021-11-25
Last seen
2026-10-03
Threat actors
186In the threats using it
Detection rules
678Blue tier and above

Data as of:

Activity timeline

T1036 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 275 reports, and 844 of the 845 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1036 Masquerading is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 845 of 2623 tracked threats (32.2%) to it; by severity that is 251 critical, 492 high, 94 medium, 5 low.

Threats that use T1036 most often also use T1027 Obfuscated Files or Information (567 threats), T1059 Command and Scripting Interpreter (539 threats), T1071 Application Layer Protocol (522 threats), T1005 Data from Local System (491 threats), T1082 System Information Discovery (468 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

186 tracked threat actors appear in the threats that use T1036; the most frequent are TeamPCP (30), APT38 (19), Sapphire Sleet (15), Stardust Chollima (15), Lazarus Group (13).

Mitigations

MITRE ATT&CK lists 8 mitigations for T1036.

Data sources

Telemetry that can reveal T1036, per MITRE ATT&CK.

  • Command — Command Execution
  • File — File Metadata, File Modification
  • Image — Image Metadata
  • Process — OS API Execution, Process Creation, Process Metadata
  • Scheduled Job — Scheduled Job Metadata, Scheduled Job Modification
  • Service — Service Creation, Service Metadata
  • User Account — User Account Creation

Threat actors using it

Tracked threats

The 30 most recent of 845 tracked threats that use T1036.

Detection coverage

Threadlinqs maintains 678 detection rules mapped to T1036 (SPL 249, KQL 188, Sigma 241). Rule content is available to Blue tier accounts and above; this page shows counts only.

678 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques