Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.010 Regsvr32 |
GroupKimsuky | Kimsuky has executed malware with |
| T1218.010 Regsvr32 |
GroupAPT32 | APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor. |
| T1218.010 Regsvr32 |
GroupLeviathan | Leviathan has used regsvr32 for execution. |
| T1218.010 Regsvr32 |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe. |
| T1218.010 Regsvr32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe. |
| T1218.010 Regsvr32 |
GroupTA551 | TA551 has used regsvr32.exe to load malicious DLLs. |
| T1218.010 Regsvr32 |
GroupDeep Panda | Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks. |
| T1218.010 Regsvr32 |
GroupCobalt Group | Cobalt Group has used regsvr32.exe to execute scripts. |
| T1218.010 Regsvr32 |
GroupInception | Inception has ensured persistence at system boot by setting the value |
| T1218.010 Regsvr32 |
GroupWIRTE | WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script. |
| T1218.010 Regsvr32 |
GroupAPT19 | APT19 used Regsvr32 to bypass application control techniques. |
| T1218.010 Regsvr32 |
MalwareOrz | Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload. |
| T1218.010 Regsvr32 |
MalwareTONESHELL | TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function. |
| T1218.010 Regsvr32 |
MalwareAppleSeed | AppleSeed can call regsvr32.exe for execution. |
| T1218.010 Regsvr32 |
MalwareEmotet | Emotet uses RegSvr32 to execute the DLL payload. |
| T1218.010 Regsvr32 |
MalwareSquirrelwaffle | Squirrelwaffle has been executed using `regsvr32.exe`. |
| T1218.010 Regsvr32 |
MalwareRaspberry Robin | Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes. |
| T1218.010 Regsvr32 |
MalwareRagnar Locker | Ragnar Locker has used regsvr32.exe to execute components of VirtualBox. |
| T1218.010 Regsvr32 |
MalwareHi-Zor | Hi-Zor executes using regsvr32.exe called from the Registry Run Keys / Startup Folder persistence mechanism. |
| T1218.010 Regsvr32 |
MalwareXbash | Xbash can use regsvr32 for executing scripts. |
| T1218.010 Regsvr32 |
MalwareSaint Bot | Saint Bot has used `regsvr32` to execute scripts. |
| T1218.010 Regsvr32 |
MalwareEVILNUM | EVILNUM can run a remote scriptlet that drops a file and executes it via regsvr32.exe. |
| T1218.010 Regsvr32 |
MalwareMori | Mori can use `regsvr32.exe` for DLL execution. |
| T1218.010 Regsvr32 |
MalwareRogueRobin | RogueRobin uses regsvr32.exe to run a .sct file for execution. |
| T1218.010 Regsvr32 |
MalwareDerusbi | Derusbi variants have been seen that use Registry persistence to proxy execution through regsvr32.exe. |
| T1218.010 Regsvr32 |
MalwareValak | Valak has used |
| T1218.010 Regsvr32 |
MalwareMore_eggs | More_eggs has used regsvr32.exe to execute the malicious DLL. |
| T1218.010 Regsvr32 |
MalwareEgregor | Egregor has used regsvr32.exe to execute malicious DLLs. |
| T1218.010 Regsvr32 |
MalwareAstaroth | Astaroth can be loaded through regsvr32.exe. |
| T1218.010 Regsvr32 |
MalwareQakBot | QakBot can use Regsvr32 to execute malicious DLLs. |
| T1218.010 Regsvr32 |
MalwareDridex | Dridex can use `regsvr32.exe` to initiate malicious code. |
| T1218.010 Regsvr32 |
MalwareHermeticWizard | HermeticWizard has used `regsvr32.exe /s /i` to execute malicious payloads. |
| T1218.010 Regsvr32 |
ToolCovenant | Covenant can create SCT files for installation via `Regsvr32` to deploy new Grunt listeners. |
| T1218.010 Regsvr32 |
ToolKoadic | Koadic can use Regsvr32 to execute additional payloads. |
| T1218.011 Rundll32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`. |
| T1218.011 Rundll32 |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used a backdoor which could execute a supplied DLL using `rundll32.exe`. |
| T1218.011 Rundll32 |
CampaignOperation Spalax | During Operation Spalax, the threat actors used `rundll32.exe` to execute malicious installers. |
| T1218.011 Rundll32 |
CampaignC0018 | During C0018, the threat actors used `rundll32` to run Mimikatz. |
| T1218.011 Rundll32 |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution utilizes rundll32.exe to execute the final Pikabot payload, using the named exports `Crash` or `Limit` depending on the variant. |
| T1218.011 Rundll32 |
CampaignC0021 | During C0021, the threat actors used `rundll32.exe` to execute the Cobalt Strike Beacon loader DLL. |
| T1218.011 Rundll32 |
CampaignC0015 | During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process. |
| T1218.011 Rundll32 |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads. |
| T1218.011 Rundll32 |
GroupAPT38 | APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools. |
| T1218.011 Rundll32 |
GroupAPT3 | APT3 has a tool that can run DLLs. |
| T1218.011 Rundll32 |
GroupKimsuky | Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network. |
| T1218.011 Rundll32 |
GroupAPT41 | APT41 has used rundll32.exe to execute a loader. |
| T1218.011 Rundll32 |
GroupAPT32 | APT32 malware has used rundll32.exe to execute an initial infection process. |
| T1218.011 Rundll32 |
GroupHAFNIUM | HAFNIUM has used |
| T1218.011 Rundll32 |
GroupMuddyWater | MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll. |
| T1218.011 Rundll32 |
GroupGamaredon Group | Gamaredon Group malware has used rundll32 to launch additional malicious components. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.