Activity timeline
T1036 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 275 reports, and 844 of the 845 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1036 Masquerading is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 845 of 2623 tracked threats (32.2%) to it; by severity that is 251 critical, 492 high, 94 medium, 5 low.
Threats that use T1036 most often also use T1027 Obfuscated Files or Information (567 threats), T1059 Command and Scripting Interpreter (539 threats), T1071 Application Layer Protocol (522 threats), T1005 Data from Local System (491 threats), T1082 System Information Discovery (468 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
186 tracked threat actors appear in the threats that use T1036; the most frequent are TeamPCP (30), APT38 (19), Sapphire Sleet (15), Stardust Chollima (15), Lazarus Group (13).
Mitigations
MITRE ATT&CK lists 8 mitigations for T1036.
Data sources
Telemetry that can reveal T1036, per MITRE ATT&CK.
- Command — Command Execution
- File — File Metadata, File Modification
- Image — Image Metadata
- Process — OS API Execution, Process Creation, Process Metadata
- Scheduled Job — Scheduled Job Metadata, Scheduled Job Modification
- Service — Service Creation, Service Metadata
- User Account — User Account Creation
Threat actors using it
Tracked threats
The 30 most recent of 845 tracked threats that use T1036.
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishingmedium
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)high
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplacemedium
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Usersmedium
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac usershigh
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…high
- Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnelhigh
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…medium
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flowmedium
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- CVE-2026-27540: Unauthenticated Arbitrary File Upload in WooCommerce Wholesale Lead Capture Plugin Actively…critical
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…high
- GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…high
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonationhigh
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvestershigh
- SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attackshigh
- ClickFix Lures Deploy MacSync Stealer to Bypass macOS Securityhigh
- Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teamsmedium
Detection coverage
Threadlinqs maintains 678 detection rules mapped to T1036 (SPL 249, KQL 188, Sigma 241). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1036.001 Invalid Code Signature — 13 tracked threats
- T1036.002 Right-to-Left Override — 2 tracked threats
- T1036.003 Rename Legitimate Utilities — 22 tracked threats
- T1036.004 Masquerade Task or Service — 25 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — 475 tracked threats
- T1036.006 Space after Filename — 1 tracked threat
- T1036.007 Double File Extension — 13 tracked threats
- T1036.008 Masquerade File Type — 24 tracked threats
- T1036.009 Break Process Trees — 0 tracked threats
- T1036.010 Masquerade Account Name — 0 tracked threats
- T1036.011 Overwrite Process Arguments — 0 tracked threats
- T1036.012 Browser Fingerprint — 0 tracked threats