# T1036.008 Masquerade File Type

> As of 2026-10-05, T1036.008 (Masquerade File Type) appears in 24 tracked threats, first reported 2026-04-30 and most recently 2026-10-03, with linked actors including APT37, APT38, Andariel; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 24 (5 critical, 18 high, 1 medium)
- **First seen:** 2026-04-30
- **Last seen:** 2026-10-03
- **Threat actors:** 11
- **Detection rules:** 65 (counts only; Blue tier and above)

## Key facts

- **ID:** T1036.008
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1036
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1036/008/

## Activity timeline

T1036.008 first appeared in tracked threats on 2026-04-30 and was most recently reported on 2026-10-03. The busiest month was 2026-09 with 9 reports, and 24 of the 24 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1036.008 Masquerade File Type is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036). Threadlinqs maps 24 of 2623 tracked threats (0.9%) to it; by severity that is 5 critical, 18 high, 1 medium.

Threats that use T1036.008 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (16 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (15 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (15 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (14 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

11 tracked threat actors appear in the threats that use T1036.008; the most frequent are [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (1), [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (1), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1036.008.

- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1036.008, per MITRE ATT&CK.

- Command — Command Execution
- File — File Modification

## Threat actors using it

- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Silver Fox APT](https://intel.threadlinqs.com/actor/Silver%20Fox%20APT) — 1
- [Star Blizzard](https://intel.threadlinqs.com/actor/Star%20Blizzard) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 1
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 1

## Tracked threats

24 tracked threats use T1036.008.

- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software](https://intel.threadlinqs.com/threat/TL-2026-2555) — high — 2026-09-17
- [Tropic Trooper Spear-Phishing Campaign Uses LNK Loader, DLL Side-Loading via Signed McAfee Binary, and…](https://intel.threadlinqs.com/threat/TL-2026-2427) — high — 2026-09-10
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry](https://intel.threadlinqs.com/threat/TL-2026-2295) — high — 2026-09-02
- [Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to…](https://intel.threadlinqs.com/threat/TL-2026-2217) — high — 2026-08-29
- [CVE-2026-15748: Forminator WordPress Plugin Arbitrary File Upload Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2052) — critical — 2026-08-17
- [Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)](https://intel.threadlinqs.com/threat/TL-2026-2040) — high — 2026-08-17
- [CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-1755) — critical — 2026-07-29
- [Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…](https://intel.threadlinqs.com/threat/TL-2026-1693) — high — 2026-07-25
- [APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installer](https://intel.threadlinqs.com/threat/TL-2026-1526) — high — 2026-07-19
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations…](https://intel.threadlinqs.com/threat/TL-2026-1354) — high — 2026-07-15
- [GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing…](https://intel.threadlinqs.com/threat/TL-2026-1179) — high — 2026-07-10
- [North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in…](https://intel.threadlinqs.com/threat/TL-2026-1111) — high — 2026-07-05
- [WinRAR 7.23 Fixes Heap Overflow in RAR5 Recovery Volume Processing (CVE-2026-14191)](https://intel.threadlinqs.com/threat/TL-2026-1063) — medium — 2026-07-02
- [PolinRider: DPRK Supply-Chain Campaign Hides BeaverTail/InvisibleFerret Malware in JS Build Config Files…](https://intel.threadlinqs.com/threat/TL-2026-1143) — critical — 2026-06-21
- [JoseCmanXD Rust Crypto Clipboard Hijacker ("silke"/"silkebin") Distributed via Fake Reputation Across…](https://intel.threadlinqs.com/threat/TL-2026-0840) — high — 2026-06-17
- [Silver Fox APT Tax-Themed Phishing — RustSL Loader, ValleyRAT & New ABCDoor Python Backdoor](https://intel.threadlinqs.com/threat/TL-2026-0443) — high — 2026-04-30

## Related CVEs

CVEs referenced by the tracked threats that use T1036.008, most frequent first.

- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-15748](https://intel.threadlinqs.com/cve/CVE-2026-15748)
- [CVE-2026-88773](https://intel.threadlinqs.com/cve/CVE-2026-88773)
- [CVE-2026-88774](https://intel.threadlinqs.com/cve/CVE-2026-88774)
- [CVE-2026-88775](https://intel.threadlinqs.com/cve/CVE-2026-88775)
- [CVE-2026-88776](https://intel.threadlinqs.com/cve/CVE-2026-88776)
- [CVE-2026-88777](https://intel.threadlinqs.com/cve/CVE-2026-88777)
- [CVE-2026-88778](https://intel.threadlinqs.com/cve/CVE-2026-88778)

## Detection coverage

Threadlinqs maintains 65 detection rules mapped to T1036.008 (SPL 24, KQL 18, Sigma 23). Rule content is available to Blue tier accounts and above; this page shows counts only.

65 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) — 845 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1036.008
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
