Threat Actors may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable Threat Actors to Subvert Trust Controls by not impacting execution controls such as digital signatures and notarization tickets.
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.