# T1036 Masquerading

> As of 2026-10-05, T1036 (Masquerading) appears in 845 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 845 (251 critical, 492 high, 94 medium, 5 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-03
- **Threat actors:** 186
- **Detection rules:** 678 (counts only; Blue tier and above)

## Key facts

- **ID:** T1036
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1036/

## Activity timeline

T1036 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 275 reports, and 844 of the 845 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1036 Masquerading is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 845 of 2623 tracked threats (32.2%) to it; by severity that is 251 critical, 492 high, 94 medium, 5 low.

Threats that use T1036 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (567 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (539 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (522 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (491 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (468 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

186 tracked threat actors appear in the threats that use T1036; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (30), [APT38](https://intel.threadlinqs.com/actor/APT38) (19), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (15), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (15), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (13).

## Mitigations

MITRE ATT&CK lists 8 mitigations for T1036.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1036, per MITRE ATT&CK.

- Command — Command Execution
- File — File Metadata, File Modification
- Image — Image Metadata
- Process — OS API Execution, Process Creation, Process Metadata
- Scheduled Job — Scheduled Job Metadata, Scheduled Job Modification
- Service — Service Creation, Service Metadata
- User Account — User Account Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 30
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 19
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 15
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 15
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 13
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 11
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 10
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 9
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 9
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 9
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 8
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 7

## Tracked threats

The 30 most recent of 845 tracked threats that use T1036.

- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — high — 2026-10-02
- [ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing](https://intel.threadlinqs.com/threat/TL-2026-2826) — medium — 2026-10-01
- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — high — 2026-09-29
- [Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)](https://intel.threadlinqs.com/threat/TL-2026-2717) — high — 2026-09-27
- [TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace](https://intel.threadlinqs.com/threat/TL-2026-2715) — medium — 2026-09-27
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac users](https://intel.threadlinqs.com/threat/TL-2026-2651) — high — 2026-09-25
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…](https://intel.threadlinqs.com/threat/TL-2026-2650) — critical — 2026-09-25
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…](https://intel.threadlinqs.com/threat/TL-2026-2645) — high — 2026-09-25
- [MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor module](https://intel.threadlinqs.com/threat/TL-2026-2641) — high — 2026-09-24
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel](https://intel.threadlinqs.com/threat/TL-2026-2609) — high — 2026-09-21
- [PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…](https://intel.threadlinqs.com/threat/TL-2026-2593) — medium — 2026-09-20
- [ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…](https://intel.threadlinqs.com/threat/TL-2026-2589) — high — 2026-09-20
- [Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow](https://intel.threadlinqs.com/threat/TL-2026-2556) — medium — 2026-09-18
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [CVE-2026-27540: Unauthenticated Arbitrary File Upload in WooCommerce Wholesale Lead Capture Plugin Actively…](https://intel.threadlinqs.com/threat/TL-2026-2539) — critical — 2026-09-16
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…](https://intel.threadlinqs.com/threat/TL-2026-2458) — high — 2026-09-12
- [Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2456) — high — 2026-09-12
- [ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-2455) — high — 2026-09-12
- [Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2452) — high — 2026-09-11
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security](https://intel.threadlinqs.com/threat/TL-2026-2434) — high — 2026-09-10
- [Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teams](https://intel.threadlinqs.com/threat/TL-2026-2430) — medium — 2026-09-10

## Related CVEs

CVEs referenced by the tracked threats that use T1036, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-48282](https://intel.threadlinqs.com/cve/CVE-2026-48282)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)

## Detection coverage

Threadlinqs maintains 678 detection rules mapped to T1036 (SPL 249, KQL 188, Sigma 241). Rule content is available to Blue tier accounts and above; this page shows counts only.

678 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1036.001 Invalid Code Signature](https://intel.threadlinqs.com/technique/T1036.001) — 13 tracked threats
- T1036.002 Right-to-Left Override — 2 tracked threats
- [T1036.003 Rename Legitimate Utilities](https://intel.threadlinqs.com/technique/T1036.003) — 22 tracked threats
- [T1036.004 Masquerade Task or Service](https://intel.threadlinqs.com/technique/T1036.004) — 25 tracked threats
- [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) — 475 tracked threats
- T1036.006 Space after Filename — 1 tracked threat
- [T1036.007 Double File Extension](https://intel.threadlinqs.com/technique/T1036.007) — 13 tracked threats
- [T1036.008 Masquerade File Type](https://intel.threadlinqs.com/technique/T1036.008) — 24 tracked threats
- T1036.009 Break Process Trees — 0 tracked threats
- T1036.010 Masquerade Account Name — 0 tracked threats
- T1036.011 Overwrite Process Arguments — 0 tracked threats
- T1036.012 Browser Fingerprint — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1036
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
