MITRE ATT&CK Technique
T1140Deobfuscate/Decode Files or Information
- First Reported
- Aug 26, 2026
- Latest Reported
- Sep 30, 2026
Official Description
Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
One such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)
Sometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)
One such example is the use of [certutil](https://attack.mitre.org/software/S0160) to decode a remote access tool portable executable file that has been hidden inside a certificate file.(Citation: Malwarebytes Targeted Attack against Saudi Arabia) Another example is using the Windows <code>copy /b</code> or <code>type</code> command to reassemble binary fragments into a malicious payload.(Citation: Carbon Black Obfuscation Sept 2016)(Citation: Sentinel One Tainted Love 2023)
Sometimes a user's action may be required to open it for deobfuscation or decryption as part of [User Execution](https://attack.mitre.org/techniques/T1204). The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.(Citation: Volexity PowerDuke November 2016)
- Tactics
- Stealth
- Platforms
- ESXi, Linux, macOS, Windows
- MITRE Version
- 2.0
- Last Modified
- May 12, 2026
Reported Context (6)
- Delivery Arm B decrypts an embedded payload from a PNG polyglot using the malfexteam2027 key. MALFEX: Malicious npm Supply-Chain Campaign Went Unadvised for 14 Months
- 2CLoader applies two XOR layers and AES-GCM decryption to recover its embedded payload. 2CLoader Malware Loader Uses Evasion and Injection to Deliver Vidar and Remus
- The PowerShell script extracts and decrypts the loader embedded in the PNG before executing it. Phishing Emails Use Fake Purchase Requests to Deliver Remcos RAT
- PowerShell restores obfuscated commands, and the loader XOR-decrypts a payload before executing it in memory. Phishing Quote Requests Deliver Remcos RAT via Obfuscated PowerShell
- The Android APK decodes its embedded APK using an XOR key, while the Windows loader decodes the Base64 executable before loading it. Fake National Health Service Site Delivers StreamRat on Android and XWorm on Windows
CVE (2)
Malware (10)
Threat Actors (2)
MITRE ATT&CK (36)
Vendors (8)
Products (18)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.