ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1218.010
Regsvr32
GroupKimsuky

Kimsuky has executed malware with regsvr32s.

T1218.010
Regsvr32
GroupAPT32

APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor.

T1218.010
Regsvr32
GroupLeviathan

Leviathan has used regsvr32 for execution.

T1218.010
Regsvr32
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe.

T1218.010
Regsvr32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe.

T1218.010
Regsvr32
GroupTA551

TA551 has used regsvr32.exe to load malicious DLLs.

T1218.010
Regsvr32
GroupDeep Panda

Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks.

T1218.010
Regsvr32
GroupCobalt Group

Cobalt Group has used regsvr32.exe to execute scripts.

T1218.010
Regsvr32
GroupInception

Inception has ensured persistence at system boot by setting the value regsvr32 %path%\ctfmonrn.dll /s.

T1218.010
Regsvr32
GroupWIRTE

WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script.

T1218.010
Regsvr32
GroupAPT19

APT19 used Regsvr32 to bypass application control techniques.

T1218.010
Regsvr32
MalwareOrz

Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload.

T1218.010
Regsvr32
MalwareTONESHELL

TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function.

T1218.010
Regsvr32
MalwareAppleSeed

AppleSeed can call regsvr32.exe for execution.

T1218.010
Regsvr32
MalwareEmotet

Emotet uses RegSvr32 to execute the DLL payload.

T1218.010
Regsvr32
MalwareSquirrelwaffle

Squirrelwaffle has been executed using `regsvr32.exe`.

T1218.010
Regsvr32
MalwareRaspberry Robin

Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes.

T1218.010
Regsvr32
MalwareRagnar Locker

Ragnar Locker has used regsvr32.exe to execute components of VirtualBox.

T1218.010
Regsvr32
MalwareHi-Zor

Hi-Zor executes using regsvr32.exe called from the Registry Run Keys / Startup Folder persistence mechanism.

T1218.010
Regsvr32
MalwareXbash

Xbash can use regsvr32 for executing scripts.

T1218.010
Regsvr32
MalwareSaint Bot

Saint Bot has used `regsvr32` to execute scripts.

T1218.010
Regsvr32
MalwareEVILNUM

EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe.

T1218.010
Regsvr32
MalwareMori

Mori can use `regsvr32.exe` for DLL execution.

T1218.010
Regsvr32
MalwareRogueRobin

RogueRobin uses regsvr32.exe to run a .sct file for execution.

T1218.010
Regsvr32
MalwareDerusbi

Derusbi variants have been seen that use Registry persistence to proxy execution through regsvr32.exe.

T1218.010
Regsvr32
MalwareValak

Valak has used regsvr32.exe to launch malicious DLLs.

T1218.010
Regsvr32
MalwareMore_eggs

More_eggs has used regsvr32.exe to execute the malicious DLL.

T1218.010
Regsvr32
MalwareEgregor

Egregor has used regsvr32.exe to execute malicious DLLs.

T1218.010
Regsvr32
MalwareAstaroth

Astaroth can be loaded through regsvr32.exe.

T1218.010
Regsvr32
MalwareQakBot

QakBot can use Regsvr32 to execute malicious DLLs.

T1218.010
Regsvr32
MalwareDridex

Dridex can use `regsvr32.exe` to initiate malicious code.

T1218.010
Regsvr32
MalwareHermeticWizard

HermeticWizard has used `regsvr32.exe /s /i` to execute malicious payloads.

T1218.010
Regsvr32
ToolCovenant

Covenant can create SCT files for installation via `Regsvr32` to deploy new Grunt listeners.

T1218.010
Regsvr32
ToolKoadic

Koadic can use Regsvr32 to execute additional payloads.

T1218.011
Rundll32
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`.

T1218.011
Rundll32
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used a backdoor which could execute a supplied DLL using `rundll32.exe`.

T1218.011
Rundll32
CampaignOperation Spalax

During Operation Spalax, the threat actors used `rundll32.exe` to execute malicious installers.

T1218.011
Rundll32
CampaignC0018

During C0018, the threat actors used `rundll32` to run Mimikatz.

T1218.011
Rundll32
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution utilizes rundll32.exe to execute the final Pikabot payload, using the named exports `Crash` or `Limit` depending on the variant.

T1218.011
Rundll32
CampaignC0021

During C0021, the threat actors used `rundll32.exe` to execute the Cobalt Strike Beacon loader DLL.

T1218.011
Rundll32
CampaignC0015

During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process.

T1218.011
Rundll32
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads.

T1218.011
Rundll32
GroupAPT38

APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools.

T1218.011
Rundll32
GroupAPT3

APT3 has a tool that can run DLLs.

T1218.011
Rundll32
GroupKimsuky

Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network.

T1218.011
Rundll32
GroupAPT41

APT41 has used rundll32.exe to execute a loader.

T1218.011
Rundll32
GroupAPT32

APT32 malware has used rundll32.exe to execute an initial infection process.

T1218.011
Rundll32
GroupHAFNIUM

HAFNIUM has used rundll32 to load malicious DLLs.

T1218.011
Rundll32
GroupMuddyWater

MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll.

T1218.011
Rundll32
GroupGamaredon Group

Gamaredon Group malware has used rundll32 to launch additional malicious components.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.