Tag
high
advisory
Suspicious Process Masquerading as SvcHost.exe
2 rules 1 TTPAdversaries are masquerading malicious processes as 'svchost.exe' by naming their binaries 'svchost.exe' and executing them from uncommon locations to evade detection.
Windows
process-masquerading
defense-evasion
svchost
2r
1t
medium
threat
Flax Typhoon Masquerading SoftEther VPN as Legitimate Windows Binaries
2 rules 2 TTPsThe Flax Typhoon group uses SoftEther VPN, masquerading the VPN client as legitimate Windows binaries like conhost.exe and dllhost.exe, to obfuscate their network activity within compromised Taiwanese organizations.
SoftEther VPN +3
Flax Typhoon
+1
flax-typhoon
defense-evasion
lateral-movement
vpn
process-masquerading
2r
2t