# T1036.001 Invalid Code Signature

> As of 2026-10-05, T1036.001 (Invalid Code Signature) appears in 13 tracked threats, first reported 2026-04-10 and most recently 2026-09-29, with linked actors including The Gentlemen, Jade Sleet, Mustang Panda; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 13 (2 critical, 8 high, 3 medium)
- **First seen:** 2026-04-10
- **Last seen:** 2026-09-29
- **Threat actors:** 10
- **Detection rules:** 15 (counts only; Blue tier and above)

## Key facts

- **ID:** T1036.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1036
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1036/001/

## Activity timeline

T1036.001 first appeared in tracked threats on 2026-04-10 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 5 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1036.001 Invalid Code Signature is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 8 high, 3 medium.

Threats that use T1036.001 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (9 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (8 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (7 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (7 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

10 tracked threat actors appear in the threats that use T1036.001; the most frequent are [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (2), [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) (1), [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) (1), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (1), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1036.001.

- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)

## Data sources

Telemetry that can reveal T1036.001, per MITRE ATT&CK.

- File — File Metadata

## Threat actors using it

- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 2
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1
- [TraderTraitor](https://intel.threadlinqs.com/actor/TraderTraitor) — 1
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 1
- [UNC6780](https://intel.threadlinqs.com/actor/UNC6780) — 1
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 1

## Tracked threats

13 tracked threats use T1036.001.

- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — high — 2026-09-29
- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — high — 2026-09-26
- [BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2](https://intel.threadlinqs.com/threat/TL-2026-2520) — high — 2026-09-15
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01
- [GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruex](https://intel.threadlinqs.com/threat/TL-2026-2059) — medium — 2026-08-18
- [June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…](https://intel.threadlinqs.com/threat/TL-2026-1353) — medium — 2026-07-15
- [AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver…](https://intel.threadlinqs.com/threat/TL-2026-1344) — high — 2026-07-15
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…](https://intel.threadlinqs.com/threat/TL-2026-1332) — high — 2026-07-14
- [Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)](https://intel.threadlinqs.com/threat/TL-2026-1183) — medium — 2026-07-10
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [GentleKiller BYOVD EDR-Killing Framework Operated by The Gentlemen RaaS (hastalamuerte / Qilin lineage)](https://intel.threadlinqs.com/threat/TL-2026-0893) — high — 2026-06-21
- [Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace\[.\]cloud Operation…](https://intel.threadlinqs.com/threat/TL-2026-0533) — high — 2026-05-19
- [Fake Claude AI Download Site Delivers Trojanized Installer Deploying PlugX RAT via G DATA DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-0349) — high — 2026-04-10

## Related CVEs

CVEs referenced by the tracked threats that use T1036.001, most frequent first.

- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)

## Detection coverage

Threadlinqs maintains 15 detection rules mapped to T1036.001 (SPL 3, KQL 5, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

15 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) — 845 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1036.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
