Activity timeline
T1036.007 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 13 of the 13 threats were reported in the twelve months to 2026-07.
How adversaries use it
T1036.007 Double File Extension is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1036 Masquerading. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 12 high, 1 medium.
Threats that use T1036.007 most often also use T1204.002 Malicious File (13 threats), T1071.001 Web Protocols (11 threats), T1027 Obfuscated Files or Information (10 threats), T1082 System Information Discovery (10 threats), T1105 Ingress Tool Transfer (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1036.007; the most frequent are APT43 (2), Gamaredon (2), Kimsuky (2), APT29 (1), APT37 (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1036.007.
Data sources
Telemetry that can reveal T1036.007, per MITRE ATT&CK.
- File — File Creation, File Metadata
Threat actors using it
Tracked threats
13 tracked threats use T1036.007.
- UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malwarehigh
- Exposed Server Reveals AI-Assisted WebDAV Phishing Kit Targeting Mexican Users (CVE-2025-33053)high
- FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC Malwarehigh
- CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code Executionhigh
- Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process…high
- Domestic APT Spear-Phishing Campaigns (May 2026) — LNK/HTA/CHM/JSE Loaders Deploying XenoRAT, Suspected…high
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- VEIL#DROP Campaign Uses Blogger-Hosted Stager to Deliver PureLogs Stealermedium
- Multi-Stage Steganographic Loader Delivers Remcos RAT and Rotating Infostealers via .NET Bitmap Resource…high
- 7-Zip NTFS Handler Heap Overflow CVE-2026-48095 — vtable Hijack via Crafted Archive (GHSL-2026-140)high
- Operation Dragon Whistle — UNG0002 Spear-Phishes Changzhou University via LNK + VBS + DLL Sideloading Chain…high
- Screensaver (.SCR) Files Used as Initial Access Vectorhigh
- DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web…high
Detection coverage
Threadlinqs maintains 32 detection rules mapped to T1036.007 (SPL 12, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1036 Masquerading — 845 tracked threats at the technique level.