Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1137.006 Add-ins |
MalwareLunarLoader | LunarLoader has the ability to use Microsoft Outlook add-ins to establish persistence. |
| T1137.006 Add-ins |
MalwareBisonal | Bisonal has been loaded through a `.wll` extension added to the ` %APPDATA%\microsoft\word\startup\` repository. |
| T1137.006 Add-ins |
MalwareLunarMail | LunarMail has the ability to use Outlook add-ins for persistence. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors decrypted scripts prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignFrankenstein | During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Honeybee | During Operation Honeybee, malicious files were decoded prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Dust Storm | During Operation Dust Storm, attackers used VBS code to decode payloads. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Spalax | For Operation Spalax, the threat actors used a variety of packers and droppers to decrypt malicious payloads. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution used highly obfuscated JavaScript files as one initial installer for Pikabot. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0021 | During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignJuicy Mix | During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignArcaneDoor | ArcaneDoor involved the use of Base64 obfuscated scripts and commands. |
| T1140 Deobfuscate/Decode Files or Information |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0017 | During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT38 | APT38 has used the RC4 algorithm to decrypt configuration data. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBlackByte | BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender. |
| T1140 Deobfuscate/Decode Files or Information |
GroupKimsuky | Kimsuky has decoded malicious VBScripts using Base64. Kimsuky has also decoded malicious PowerShell scripts using Base64. Kimsuky has decoded RC4 obfuscated files prior to downloading files from their infrastructure. |
| T1140 Deobfuscate/Decode Files or Information |
GroupVolt Typhoon | Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil. |
| T1140 Deobfuscate/Decode Files or Information |
GroupGorgon Group | Gorgon Group malware can decode contents from a payload that was Base64 encoded and write the contents to a file. |
| T1140 Deobfuscate/Decode Files or Information |
GroupmenuPass | menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used |
| T1140 Deobfuscate/Decode Files or Information |
GroupMuddyWater | MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript. |
| T1140 Deobfuscate/Decode Files or Information |
GroupGamaredon Group | Gamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded Base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
GroupStorm-1811 | Storm-1811 has distributed password-protected archives such as ZIP files during intrusions. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTeamTNT | TeamTNT has used a script that decodes a Base64-encoded version of WeaveWorks Scope. |
| T1140 Deobfuscate/Decode Files or Information |
GroupFIN7 | FIN7 has decoded a malicious PowerShell script using `certutil -decode hex` and has decoded an XOR-obfuscated block of data with the key `qawsed1q2w3e`, which led to the installation of Lizar. |
| T1140 Deobfuscate/Decode Files or Information |
GroupSandworm Team | Sandworm Team's VBS backdoor can decode Base64-encoded data and save it to the %TEMP% folder. The group also decrypted received information using the Triple DES algorithm and decompresses it using GZip. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMustang Panda | Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads. |
| T1140 Deobfuscate/Decode Files or Information |
GroupZIRCONIUM | ZIRCONIUM has used the AES256 algorithm with a SHA1 derived key to decrypt exploit code. |
| T1140 Deobfuscate/Decode Files or Information |
GroupRocke | Rocke has extracted tar.gz files after downloading them from a C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT39 | APT39 has used malware to decrypt encrypted CAB files. |
| T1140 Deobfuscate/Decode Files or Information |
GroupOilRig | A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims. |
| T1140 Deobfuscate/Decode Files or Information |
GroupHigaisa | Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTropic Trooper | Tropic Trooper used shellcode with an XOR algorithm to decrypt a payload. Tropic Trooper also decrypted image files which contained a payload. |
| T1140 Deobfuscate/Decode Files or Information |
GroupKe3chang | Ke3chang has deobfuscated Base64-encoded shellcode strings prior to loading them. |
| T1140 Deobfuscate/Decode Files or Information |
GroupLeviathan | Leviathan has used a DLL known as SeDll to decrypt and execute other JavaScript backdoors. |
| T1140 Deobfuscate/Decode Files or Information |
GroupWinter Vivern | Winter Vivern delivered exploit payloads via base64-encoded payloads in malicious email messages. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTurla | Turla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTA505 | TA505 has decrypted packed DLLs with an XOR key. |
| T1140 Deobfuscate/Decode Files or Information |
GroupCinnamon Tempest | Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBRONZE BUTLER | BRONZE BUTLER downloads encoded payloads and decodes them on the victim. |
| T1140 Deobfuscate/Decode Files or Information |
GroupDarkhotel | Darkhotel has decrypted strings and imports using RC4 during execution. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAgrius | Agrius has deployed base64-encoded variants of ASPXSpy to evade detection. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT28 | An APT28 macro uses the command |
| T1140 Deobfuscate/Decode Files or Information |
GroupMalteiro | Malteiro has the ability to deobfuscate downloaded files prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
GroupLazarus Group | Lazarus Group has used shellcode within macros to decrypt and manually map DLLs and shellcode into memory at runtime. |
| T1140 Deobfuscate/Decode Files or Information |
GroupEarth Lusca | Earth Lusca has used certutil to decode a string into a cabinet file. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMolerats | Molerats decompresses ZIP files once on the victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.