MITRE ATT&CK ICS
T0849

Masquerading

Description

Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion. Possible disguises of these masquerading files can include commonly found programs, expected vendor executables and configuration files, and other commonplace application and naming conventions. By impersonating expected and vendor-relevant files and applications, operators and engineers may not notice the presence of the underlying malicious content and possibly end up running those masquerading as legitimate functions. Applications and other files commonly found on Windows systems or in engineering workstations have been impersonated before. This can be as simple as renaming a file to effectively disguise it in the ICS environment.

Mapped SPARTA techniques

2 techniques

  • DE-0004MasqueradingST0006
    addresses
    high

    T0849 'Masquerading' is the exact-title-and-scope ATT&CK ICS evasion-tactic technique; SPARTA DE-0004 'Masquerading' is the same activity at cross-framework level (adversary commands/components disguised as legitimate). Tactic and activity align directly.

  • DE-0012Component CollusionST0006
    addresses
    moderate

    T0849 'Masquerading' addresses adversary disguising malicious applications/executables as legitimate; SPARTA DE-0012 'Component Collusion' is multiple compromised components collectively presenting as legitimate — concept-adjacent but broader. Moderate confidence honors that DE-0012's collective-collusion aspect is not fully captured by single-component masquerading.

Cite as SafeMode Space, mitre-attack-ics T0849.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.