Activity timeline
T1036.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 9 reports, and 22 of the 22 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1036.003 Rename Legitimate Utilities is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1036 Masquerading. Threadlinqs maps 22 of 2623 tracked threats (0.8%) to it; by severity that is 4 critical, 17 high, 1 medium.
Threats that use T1036.003 most often also use T1071.001 Web Protocols (18 threats), T1082 System Information Discovery (16 threats), T1036.005 Match Legitimate Resource Name or Location (14 threats), T1105 Ingress Tool Transfer (14 threats), T1140 Deobfuscate/Decode Files or Information (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
18 tracked threat actors appear in the threats that use T1036.003; the most frequent are APT38 (2), Sapphire Sleet (2), Stardust Chollima (2), APT10 (1), Akira (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1036.003.
Data sources
Telemetry that can reveal T1036.003, per MITRE ATT&CK.
- Command — Command Execution
- File — File Metadata, File Modification
- Process — Process Metadata
Threat actors using it
Tracked threats
22 tracked threats use T1036.003.
- DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganographyhigh
- North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean…high
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…critical
- SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machineshigh
- Odyssey Piracy Scam Campaign: Malvertising and Icon-Spoofed Executables Targeting Movie Downloadersmedium
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering…high
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaignhigh
- ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector…high
- Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and…high
- Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…high
- FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT…critical
- Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US…high
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- Stealthy P2P Cryptominer Targeting Ollama Endpoints — Custom Go-Based 'vc' RAT/Dropper (Akamai SIRT)high
- BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by…high
- JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…high
- Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT…critical
- CSVDE.exe LOLBIN for Active Directory Reconnaissance — FIN7 + APT10/menuPass Documented Usage, Bulk LDAP…high
- CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS…critical
- BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest…high
- DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web…high
Detection coverage
Threadlinqs maintains 41 detection rules mapped to T1036.003 (SPL 18, KQL 11, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1036 Masquerading — 845 tracked threats at the technique level.