Activity timeline
T1036.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 9 reports, and 25 of the 25 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1036.004 Masquerade Task or Service is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1036 Masquerading. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 6 critical, 19 high.
Threats that use T1036.004 most often also use T1082 System Information Discovery (20 threats), T1105 Ingress Tool Transfer (19 threats), T1041 Exfiltration Over C2 Channel (18 threats), T1071.001 Web Protocols (18 threats), T1027 Obfuscated Files or Information (17 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
14 tracked threat actors appear in the threats that use T1036.004; the most frequent are APT36 (1), APT38 (1), APT44 (1), Andariel (1), Gamaredon (1).
Data sources
Telemetry that can reveal T1036.004, per MITRE ATT&CK.
- Command — Command Execution
- Scheduled Job — Scheduled Job Metadata, Scheduled Job Modification
- Service — Service Creation, Service Metadata
Threat actors using it
Tracked threats
25 tracked threats use T1036.004.
- BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…high
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)high
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…high
- macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain…high
- Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to…high
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…high
- RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chainhigh
- Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…high
- ClickFix macOS Trio: Loader/Script/Helper Campaigns Deliver SHub Stealer, AMOS, and Macsync Stealer with…high
- Operation Silent Rotor — Rust-based Spear-Phishing Loader Targeting Eurasian Unmanned Aviation Sector Ahead…high
- Remcos RAT Phishing Campaign Abusing Google Cloud Storage (storage.googleapis.com) with RegSvcs.exe Process…high
- Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT…critical
- EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interviewcritical
- UAC-0252 SHADOWSNIFF & SALATSTEALER — Credential Theft Campaign Impersonating Ukrainian Government via…high
- State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database…high
Detection coverage
Threadlinqs maintains 56 detection rules mapped to T1036.004 (SPL 22, KQL 20, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1036 Masquerading — 845 tracked threats at the technique level.