Activity timeline
T1036.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1036.001 Invalid Code Signature is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1036 Masquerading. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 8 high, 3 medium.
Threats that use T1036.001 most often also use T1027 Obfuscated Files or Information (9 threats), T1204.002 Malicious File (8 threats), T1071.001 Web Protocols (7 threats), T1082 System Information Discovery (7 threats), T1140 Deobfuscate/Decode Files or Information (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
10 tracked threat actors appear in the threats that use T1036.001; the most frequent are The Gentlemen (2), Jade Sleet (1), Mustang Panda (1), Sapphire Sleet (1), Stardust Chollima (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1036.001.
Data sources
Telemetry that can reveal T1036.001, per MITRE ATT&CK.
- File — File Metadata
Threat actors using it
Tracked threats
13 tracked threats use T1036.001.
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)high
- BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2high
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…critical
- GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruexmedium
- June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…medium
- AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver…high
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…high
- Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)medium
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- GentleKiller BYOVD EDR-Killing Framework Operated by The Gentlemen RaaS (hastalamuerte / Qilin lineage)high
- Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace[.]cloud Operation…high
- Fake Claude AI Download Site Delivers Trojanized Installer Deploying PlugX RAT via G DATA DLL Sideloadinghigh
Detection coverage
Threadlinqs maintains 15 detection rules mapped to T1036.001 (SPL 3, KQL 5, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1036 Masquerading — 845 tracked threats at the technique level.