Linux Process Name Masquerading, (Wed, Jun 24th)
2026-06-24T19:23:46Z•a18bffada6421228982ab3a91711134980083b05ebcc5af8dda43c8148524b59
MITRE-ATT&CKMITRE-T1036Velvet Antdefense-evasionlinuxmalware-obfuscationmasqueradingprocess-hidingprocess-masqueradingrootkit
What happened
Diary entry on Linux process name masquerading: attackers can replace or spoof process names to make malicious processes appear benign, defeating simple process-listing checks. The technique maps to MITRE ATT&CK T1036 (Masquerading) and is used alongside rootkits (which can tamper with APIs/commands to hide processes). The author cites Velvet Ant as an example and emphasizes malware obfuscation and the risk of trusting process listings for detection.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- a18bffada6421228982ab3a91711134980083b05ebcc5af8dda43c8148524b59
- Enrichment time
- 2026-06-24T19:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.