ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1140×

14 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors decrypted scripts prior to execution.

T1140
Deobfuscate/Decode Files or Information
CampaignFrankenstein

During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload.

T1140
Deobfuscate/Decode Files or Information
CampaignRedPenguin

During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives.

T1140
Deobfuscate/Decode Files or Information
CampaignOperation Honeybee

During Operation Honeybee, malicious files were decoded prior to execution.

T1140
Deobfuscate/Decode Files or Information
CampaignOperation Dust Storm

During Operation Dust Storm, attackers used VBS code to decode payloads.

T1140
Deobfuscate/Decode Files or Information
CampaignOperation Spalax

For Operation Spalax, the threat actors used a variety of packers and droppers to decrypt malicious payloads.

T1140
Deobfuscate/Decode Files or Information
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution used highly obfuscated JavaScript files as one initial installer for Pikabot.

T1140
Deobfuscate/Decode Files or Information
CampaignC0021

During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64.

T1140
Deobfuscate/Decode Files or Information
CampaignJuicy Mix

During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango.

T1140
Deobfuscate/Decode Files or Information
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware.

T1140
Deobfuscate/Decode Files or Information
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR.

T1140
Deobfuscate/Decode Files or Information
CampaignArcaneDoor

ArcaneDoor involved the use of Base64 obfuscated scripts and commands.

T1140
Deobfuscate/Decode Files or Information
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil.

T1140
Deobfuscate/Decode Files or Information
CampaignC0017

During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.