Real-world descriptions of how a group, tool or campaign used a technique.
14 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors decrypted scripts prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignFrankenstein | During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Honeybee | During Operation Honeybee, malicious files were decoded prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Dust Storm | During Operation Dust Storm, attackers used VBS code to decode payloads. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Spalax | For Operation Spalax, the threat actors used a variety of packers and droppers to decrypt malicious payloads. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution used highly obfuscated JavaScript files as one initial installer for Pikabot. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0021 | During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignJuicy Mix | During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignArcaneDoor | ArcaneDoor involved the use of Base64 obfuscated scripts and commands. |
| T1140 Deobfuscate/Decode Files or Information |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0017 | During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.