Activity timeline
T1140 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 252 reports, and 718 of the 720 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1140 Deobfuscate/Decode Files or Information is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 720 of 2623 tracked threats (27.4%) to it; by severity that is 172 critical, 492 high, 52 medium, 3 low.
Threats that use T1140 most often also use T1027 Obfuscated Files or Information (568 threats), T1082 System Information Discovery (490 threats), T1005 Data from Local System (450 threats), T1041 Exfiltration Over C2 Channel (420 threats), T1105 Ingress Tool Transfer (408 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
152 tracked threat actors appear in the threats that use T1140; the most frequent are APT38 (24), Sapphire Sleet (19), TeamPCP (19), Stardust Chollima (17), Andariel (14).
Data sources
Telemetry that can reveal T1140, per MITRE ATT&CK.
- File — File Modification
- Process — Process Creation
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 720 tracked threats that use T1140.
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…high
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- CloudSyncD macOS Backdoor Delivered via Fake Zoom Installerhigh
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and…medium
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealerhigh
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac usershigh
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
Detection coverage
Threadlinqs maintains 651 detection rules mapped to T1140 (SPL 195, KQL 205, Sigma 249, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.