# T1036.007 Double File Extension

> As of 2026-10-05, T1036.007 (Double File Extension) appears in 13 tracked threats, first reported 2026-01-14 and most recently 2026-07-23, with linked actors including APT43, Gamaredon, Kimsuky; it most often appears alongside T1204.002 (Malicious File).

- **Tracked threats:** 13 (12 high, 1 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-07-23
- **Threat actors:** 6
- **Detection rules:** 32 (counts only; Blue tier and above)

## Key facts

- **ID:** T1036.007
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1036
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1036/007/

## Activity timeline

T1036.007 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-07-23. The busiest month was 2026-07 with 8 reports, and 13 of the 13 threats were reported in the twelve months to 2026-07.

## How adversaries use it

T1036.007 Double File Extension is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 12 high, 1 medium.

Threats that use T1036.007 most often also use [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (13 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (11 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (10 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1036.007; the most frequent are [APT43](https://intel.threadlinqs.com/actor/APT43) (2), [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) (2), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (2), [APT29](https://intel.threadlinqs.com/actor/APT29) (1), [APT37](https://intel.threadlinqs.com/actor/APT37) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1036.007.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)

## Data sources

Telemetry that can reveal T1036.007, per MITRE ATT&CK.

- File — File Creation, File Metadata

## Threat actors using it

- [APT43](https://intel.threadlinqs.com/actor/APT43) — 2
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 2
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 2
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [TA505](https://intel.threadlinqs.com/actor/TA505) — 1

## Tracked threats

13 tracked threats use T1036.007.

- [UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malware](https://intel.threadlinqs.com/threat/TL-2026-1657) — high — 2026-07-23
- [Exposed Server Reveals AI-Assisted WebDAV Phishing Kit Targeting Mexican Users (CVE-2025-33053)](https://intel.threadlinqs.com/threat/TL-2026-1566) — high — 2026-07-20
- [FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC Malware](https://intel.threadlinqs.com/threat/TL-2026-1565) — high — 2026-07-20
- [CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1428) — high — 2026-07-16
- [Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process…](https://intel.threadlinqs.com/threat/TL-2026-1285) — high — 2026-07-13
- [Domestic APT Spear-Phishing Campaigns (May 2026) — LNK/HTA/CHM/JSE Loaders Deploying XenoRAT, Suspected…](https://intel.threadlinqs.com/threat/TL-2026-1229) — high — 2026-07-11
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [VEIL#DROP Campaign Uses Blogger-Hosted Stager to Deliver PureLogs Stealer](https://intel.threadlinqs.com/threat/TL-2026-1052) — medium — 2026-07-01
- [Multi-Stage Steganographic Loader Delivers Remcos RAT and Rotating Infostealers via .NET Bitmap Resource…](https://intel.threadlinqs.com/threat/TL-2026-0939) — high — 2026-06-25
- [7-Zip NTFS Handler Heap Overflow CVE-2026-48095 — vtable Hijack via Crafted Archive (GHSL-2026-140)](https://intel.threadlinqs.com/threat/TL-2026-0586) — high — 2026-05-26
- [Operation Dragon Whistle — UNG0002 Spear-Phishes Changzhou University via LNK + VBS + DLL Sideloading Chain…](https://intel.threadlinqs.com/threat/TL-2026-0540) — high — 2026-05-20
- [Screensaver (.SCR) Files Used as Initial Access Vector](https://intel.threadlinqs.com/threat/TL-2026-0104) — high — 2026-02-16
- [DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web…](https://intel.threadlinqs.com/threat/TL-2026-0092) — high — 2026-01-14

## Related CVEs

CVEs referenced by the tracked threats that use T1036.007, most frequent first.

- [CVE-2025-24054](https://intel.threadlinqs.com/cve/CVE-2025-24054)
- [CVE-2025-33053](https://intel.threadlinqs.com/cve/CVE-2025-33053)
- [CVE-2025-56383](https://intel.threadlinqs.com/cve/CVE-2025-56383)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-48095](https://intel.threadlinqs.com/cve/CVE-2026-48095)

## Detection coverage

Threadlinqs maintains 32 detection rules mapped to T1036.007 (SPL 12, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

32 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) — 845 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1036.007
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
