ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1218.011
Rundll32
MalwareMosquito

Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability.

T1218.011
Rundll32
MalwareRTM

RTM runs its core DLL file using rundll32.exe.

T1218.011
Rundll32
MalwareStrelaStealer

StrelaStealer DLL payloads have been executed via `rundll32.exe`.

T1218.011
Rundll32
MalwareSakula

Sakula calls cmd.exe to run various DLL files via rundll32.

T1218.011
Rundll32
MalwareSibot

Sibot has executed downloaded DLLs with rundll32.exe.

T1218.011
Rundll32
MalwareKapeka

Kapeka is a Windows DLL file executed via ordinal by `rundll32.exe`.

T1218.011
Rundll32
MalwareCobalt Strike

Cobalt Strike can use `rundll32.exe` to load DLL from the command line.

T1218.011
Rundll32
MalwareSUNBURST

SUNBURST used Rundll32 to execute payloads.

T1218.011
Rundll32
MalwareServHelper

ServHelper contains a module for downloading and executing DLLs that leverages rundll32.exe.

T1218.011
Rundll32
MalwareNativeZone

NativeZone has used rundll32 to execute a malicious DLL.

T1218.011
Rundll32
MalwareFunnyDream

FunnyDream can use `rundll32` for execution of its components.

T1218.011
Rundll32
MalwareKwampirs

Kwampirs uses rundll32.exe in a Registry value added to establish persistence.

T1218.011
Rundll32
MalwareBoomBox

BoomBox can use RunDLL32 for execution.

T1218.011
Rundll32
MalwareDEADEYE

DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`.

T1218.011
Rundll32
MalwareEgregor

Egregor has used rundll32 during execution.

T1218.011
Rundll32
MalwareFELIXROOT

FELIXROOT uses Rundll32 for executing the dropper program.

T1218.011
Rundll32
MalwareZxShell

ZxShell has used rundll32.exe to execute other DLLs and named pipes.

T1218.011
Rundll32
MalwareDDKONG

DDKONG uses Rundll32 to ensure only a single instance of itself is running at once.

T1218.011
Rundll32
MalwareWinnti for Windows

The Winnti for Windows installer loads a DLL using rundll32.

T1218.011
Rundll32
MalwareTroll Stealer

Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer.

T1218.011
Rundll32
MalwareHeyoka Backdoor

Heyoka Backdoor can use rundll32.exe to gain execution.

T1218.011
Rundll32
MalwareCozyCar

The CozyCar dropper copies the system file rundll32.exe to the install location for the malware, then uses the copy of rundll32.exe to load and execute the main CozyCar component.

T1218.011
Rundll32
MalwareQakBot

QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.

T1218.011
Rundll32
MalwareComnie

Comnie uses Rundll32 to load a malicious DLL.

T1218.011
Rundll32
MalwareADVSTORESHELL

ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence.

T1218.011
Rundll32
MalwareHermeticWizard

HermeticWizard has the ability to create a new process using `rundll32`.

T1218.011
Rundll32
ToolPcShare

PcShare has used `rundll32.exe` for execution.

T1218.011
Rundll32
ToolKoadic

Koadic can use Rundll32 to execute additional payloads.

T1218.011
Rundll32
MalwareFlame

Rundll32.exe is used as a way of executing Flame at the command-line.

T1218.012
Verclsid
MalwareHancitor

Hancitor has used verclsid.exe to download and execute a malicious script.

T1218.013
Mavinject
MalwareTONESHELL

TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`.

T1218.015
Electron Applications
MalwareLumma Stealer

Lumma Stealer as leveraged Electron Applications to disable GPU sandboxing to avoid detection by security software.

T1219
Remote Access Tools
MalwareTrickBot

TrickBot uses vncDll module to remote control the victim machine.

T1219
Remote Access Tools
MalwareInvisibleFerret

InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`.

T1219
Remote Access Tools
MalwareHildegard

Hildegard has established tmate sessions for C2 communications.

T1219
Remote Access Tools
MalwareCarbanak

Carbanak has a plugin for VNC and Ammyy Admin Tool.

T1219
Remote Access Tools
MalwareRTM

RTM has the capability to download a VNC module from command and control (C2).

T1219
Remote Access Tools
MalwareEgregor

Egregor has checked for the LogMein event log in an attempt to encrypt files in remote machines.

T1219
Remote Access Tools
MalwareDridex

Dridex contains a module for VNC.

T1219.002
Remote Desktop Software
MalwareQilin

Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems.

T1220
XSL Script Processing
MalwareAstaroth

Astaroth executes embedded JScript or VBScript in an XSL stylesheet located on a remote domain.

T1221
Template Injection
MalwareChaes

Chaes changed the template target of the settings.xml file embedded in the Word document and populated that field with the downloaded URL of the next payload.

T1221
Template Injection
MalwareWarzoneRAT

WarzoneRAT has been install via template injection through a malicious DLL embedded within a template RTF in a Word document.

T1222
File and Directory Permissions Modification
MalwareQilin

Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.

T1222.001
Windows Permissions
MalwareWastedLocker

WastedLocker has a command to take ownership of a file and reset the ACL permissions using the takeown.exe /F filepath command.

T1222.001
Windows Permissions
MalwareBlackCat

BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks.

T1222.001
Windows Permissions
MalwareWannaCry

WannaCry uses attrib +h and icacls . /grant Everyone:F /T /C /Q to make some of its files hidden and grant all users full access controls.

T1222.001
Windows Permissions
MalwareBlackByte Ransomware

BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive.

T1222.001
Windows Permissions
MalwareGrandoreiro

Grandoreiro can modify the binary ACL to prevent security tools from running.

T1222.001
Windows Permissions
MalwareRyuk

Ryuk can launch icacls <path> /grant Everyone:F /T /C /Q to delete every access-based restrictions on files and directories.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.