Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.011 Rundll32 |
MalwareMosquito | Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability. |
| T1218.011 Rundll32 |
MalwareRTM | RTM runs its core DLL file using rundll32.exe. |
| T1218.011 Rundll32 |
MalwareStrelaStealer | StrelaStealer DLL payloads have been executed via `rundll32.exe`. |
| T1218.011 Rundll32 |
MalwareSakula | Sakula calls cmd.exe to run various DLL files via rundll32. |
| T1218.011 Rundll32 |
MalwareSibot | Sibot has executed downloaded DLLs with |
| T1218.011 Rundll32 |
MalwareKapeka | Kapeka is a Windows DLL file executed via ordinal by `rundll32.exe`. |
| T1218.011 Rundll32 |
MalwareCobalt Strike | Cobalt Strike can use `rundll32.exe` to load DLL from the command line. |
| T1218.011 Rundll32 |
MalwareSUNBURST | SUNBURST used Rundll32 to execute payloads. |
| T1218.011 Rundll32 |
MalwareServHelper | ServHelper contains a module for downloading and executing DLLs that leverages |
| T1218.011 Rundll32 |
MalwareNativeZone | NativeZone has used rundll32 to execute a malicious DLL. |
| T1218.011 Rundll32 |
MalwareFunnyDream | FunnyDream can use `rundll32` for execution of its components. |
| T1218.011 Rundll32 |
MalwareKwampirs | Kwampirs uses rundll32.exe in a Registry value added to establish persistence. |
| T1218.011 Rundll32 |
MalwareBoomBox | BoomBox can use RunDLL32 for execution. |
| T1218.011 Rundll32 |
MalwareDEADEYE | DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`. |
| T1218.011 Rundll32 |
MalwareEgregor | Egregor has used rundll32 during execution. |
| T1218.011 Rundll32 |
MalwareFELIXROOT | FELIXROOT uses Rundll32 for executing the dropper program. |
| T1218.011 Rundll32 |
MalwareZxShell | ZxShell has used rundll32.exe to execute other DLLs and named pipes. |
| T1218.011 Rundll32 |
MalwareDDKONG | DDKONG uses Rundll32 to ensure only a single instance of itself is running at once. |
| T1218.011 Rundll32 |
MalwareWinnti for Windows | The Winnti for Windows installer loads a DLL using rundll32. |
| T1218.011 Rundll32 |
MalwareTroll Stealer | Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer. |
| T1218.011 Rundll32 |
MalwareHeyoka Backdoor | Heyoka Backdoor can use rundll32.exe to gain execution. |
| T1218.011 Rundll32 |
MalwareCozyCar | The CozyCar dropper copies the system file rundll32.exe to the install location for the malware, then uses the copy of rundll32.exe to load and execute the main CozyCar component. |
| T1218.011 Rundll32 |
MalwareQakBot | QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication. |
| T1218.011 Rundll32 |
MalwareComnie | Comnie uses Rundll32 to load a malicious DLL. |
| T1218.011 Rundll32 |
MalwareADVSTORESHELL | ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence. |
| T1218.011 Rundll32 |
MalwareHermeticWizard | HermeticWizard has the ability to create a new process using `rundll32`. |
| T1218.011 Rundll32 |
ToolPcShare | PcShare has used `rundll32.exe` for execution. |
| T1218.011 Rundll32 |
ToolKoadic | Koadic can use Rundll32 to execute additional payloads. |
| T1218.011 Rundll32 |
MalwareFlame | Rundll32.exe is used as a way of executing Flame at the command-line. |
| T1218.012 Verclsid |
MalwareHancitor | Hancitor has used verclsid.exe to download and execute a malicious script. |
| T1218.013 Mavinject |
MalwareTONESHELL | TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`. |
| T1218.015 Electron Applications |
MalwareLumma Stealer | Lumma Stealer as leveraged Electron Applications to disable GPU sandboxing to avoid detection by security software. |
| T1219 Remote Access Tools |
MalwareTrickBot | TrickBot uses vncDll module to remote control the victim machine. |
| T1219 Remote Access Tools |
MalwareInvisibleFerret | InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`. |
| T1219 Remote Access Tools |
MalwareHildegard | Hildegard has established tmate sessions for C2 communications. |
| T1219 Remote Access Tools |
MalwareCarbanak | Carbanak has a plugin for VNC and Ammyy Admin Tool. |
| T1219 Remote Access Tools |
MalwareRTM | RTM has the capability to download a VNC module from command and control (C2). |
| T1219 Remote Access Tools |
MalwareEgregor | Egregor has checked for the LogMein event log in an attempt to encrypt files in remote machines. |
| T1219 Remote Access Tools |
MalwareDridex | Dridex contains a module for VNC. |
| T1219.002 Remote Desktop Software |
MalwareQilin | Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems. |
| T1220 XSL Script Processing |
MalwareAstaroth | Astaroth executes embedded JScript or VBScript in an XSL stylesheet located on a remote domain. |
| T1221 Template Injection |
MalwareChaes | Chaes changed the template target of the settings.xml file embedded in the Word document and populated that field with the downloaded URL of the next payload. |
| T1221 Template Injection |
MalwareWarzoneRAT | WarzoneRAT has been install via template injection through a malicious DLL embedded within a template RTF in a Word document. |
| T1222 File and Directory Permissions Modification |
MalwareQilin | Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable. |
| T1222.001 Windows Permissions |
MalwareWastedLocker | WastedLocker has a command to take ownership of a file and reset the ACL permissions using the |
| T1222.001 Windows Permissions |
MalwareBlackCat | BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks. |
| T1222.001 Windows Permissions |
MalwareWannaCry | WannaCry uses |
| T1222.001 Windows Permissions |
MalwareBlackByte Ransomware | BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive. |
| T1222.001 Windows Permissions |
MalwareGrandoreiro | Grandoreiro can modify the binary ACL to prevent security tools from running. |
| T1222.001 Windows Permissions |
MalwareRyuk | Ryuk can launch |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.