Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1406
MITRE ATT&CK Technique

T1406: Obfuscated Files or Information

ShareXLinkedInRedditHN

Adversaries may attempt to make a payload or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the device or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Portions of files can also be encoded to hide the plaintext strings that would otherwise help defenders with discovery. Payloads may also be split into separate, seemingly benign files that only reveal malicious functionality when reassembled.(Citation: Microsoft MalLockerB)

Tactics
Defense Evasion
Platforms
Android, iOS

▪Sub-techniques (2)

T1406.001SteganographyT1406.002Software Packing

▪Used by groups (1)

G0112Windshift

▪Software using this technique (46)

S0286OBADmalwareS0293BrainTestmalwareS0312WireLurkermalwareS0318XLoader for AndroidmalwareS0323ChargermalwareS0399PallasmalwareS0406GustuffmalwareS0407MonoklemalwareS0408FlexiSpytoolS0411RotexymalwareS0420DvmapmalwareS0421GolfSpymalwareS0423GinpmalwareS0427TrickMomalwareS0432BreadmalwareS0463INSOMNIAmalwareS0478EventBotmalwareS0480CerberusmalwareS0485MandrakemalwareS0489WolfRATmalwareS0494ZenmalwareS0509FakeSpymalwareS0524AndroidOS/MalLocker.BmalwareS0525Android/AdDisplay.AshasmalwareS0529CarbonStealmalwareS0536GPlayedmalwareS0539Red Alert 2.0malwareS0540AsacubmalwareS0544HenBoxmalwareS0545TERRACOTTAmalwareS0549SilkBeanmalwareS0550DoubleAgentmalwareS0555CHEMISTGAMESmalwareS1054DrinikmalwareS1055SharkBotmalwareS1056TianySpymalwareS1061AbstractEmumalwareS1067FluBotmalwareS1094BRATAmalwareS1095AhRatmalwareS1185LightSpymalwareS1195SpyC23malwareS1214Android/SpyAgentmalwareS1231GodFathermalwareS9004CrocodilusmalwareS9005DocSwapmalware

▪Reference

T1406on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.