Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Resource Name or Location |
GoBear is installed through droppers masquerading as legitimate, signed software installers.[2] |
Enterprise | T1090 | Proxy | ||
Enterprise | T1553 | .002 | Subvert Trust Controls: Code Signing |
GoBear uses stolen legitimate code signing certificates for defense evasion.[1][2] |