Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1140

T1140Deobfuscate/Decode Files or Information

T1140 — Deobfuscate/Decode Files or Information is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 15 detection use cases covering it and 16 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
16Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

[WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣPDD CertUtil With Decode Argument ESCU actions · alerting P Linux Auditd Base64 Decode Files ESCU actions · hunting P [LLM] Argamal MI_V / MI_V2 Environment Variable Stage Handoff Bespoke install · alerting DSΣPDDCS [LLM] Bun spawned from npm install context executing /tmp/p*.js implant Bespoke install · alerting DSΣPDDCS [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Kimsuky JSE dropper: wscript -> powershell hidden + certutil -decode chain Bespoke delivery · alerting DSΣPDD [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] Python spawning python -c with base64.b64decode exec (litellm .pth stage-1 launcher) Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP Linux/Mac stdin-piped Python second stage (sys.executable -) Bespoke exploit · hunting DSPDDCS [LLM] GitHub Actions runner credential stealer: python3 base64-decoded payload reading /proc/<pid>/mem Bespoke actions · hunting DSPDD [LLM] GlassWorm invisible-Unicode decoder signature (variation-selector eval loader) in process cmdline Bespoke exploit · hunting DSΣPDD [LLM] G_Wagon dropper: node.exe spawns system tar.exe extracting from stdin (-x -f - -C) Bespoke delivery · alerting DSΣPDDCS [LLM] Non-browser process reading Chrome/Edge/Opera Login Data or Local State Bespoke actions · alerting DSΣPDDCS [LLM] Malicious tj-actions base64 payload prefix observed in process command line Bespoke exploit · alerting DSΣPDDCS

Articles citing this technique (16)