ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1218.011
Rundll32
GroupFIN7

FIN7 has used `rundll32.exe` to execute malware on a compromised network.

T1218.011
Rundll32
GroupSandworm Team

Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe.

T1218.011
Rundll32
GroupUNC3886

UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory.

T1218.011
Rundll32
GroupCarbanak

Carbanak installs VNC server software that executes through rundll32.

T1218.011
Rundll32
GroupAquatic Panda

Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary.

T1218.011
Rundll32
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.

T1218.011
Rundll32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe.

T1218.011
Rundll32
GroupTA505

TA505 has leveraged rundll32.exe to execute malicious DLLs.

T1218.011
Rundll32
GroupRedCurl

RedCurl has used rundll32.exe to execute malicious files.

T1218.011
Rundll32
GroupTA551

TA551 has used rundll32.exe to load malicious DLLs.

T1218.011
Rundll32
GroupLazyScripter

LazyScripter has used `rundll32.exe` to execute Koadic stagers.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1218.011
Rundll32
GroupLazarus Group

Lazarus Group has used rundll32 to execute malicious payloads on a compromised host.

T1218.011
Rundll32
GroupCopyKittens

CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode.

T1218.011
Rundll32
GroupWizard Spider

Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV.

T1218.011
Rundll32
GroupDaggerfly

Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary.

T1218.011
Rundll32
GroupMagic Hound

Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory.

T1218.011
Rundll32
GroupAPT19

APT19 configured its payload to inject into the rundll32.exe.

T1218.011
Rundll32
MalwarePowerDuke

PowerDuke uses rundll32.exe to load.

T1218.011
Rundll32
MalwareBLINDINGCAN

BLINDINGCAN has used Rundll32 to load a malicious DLL.

T1218.011
Rundll32
MalwareNinja

Ninja loader components can be executed through rundll32.exe.

T1218.011
Rundll32
MalwareBumblebee

Bumblebee has used `rundll32` for execution of the loader component.

T1218.011
Rundll32
MalwareNOKKI

NOKKI has used rundll32 for execution.

T1218.011
Rundll32
MalwareBackdoor.Oldrea

Backdoor.Oldrea can use rundll32 for execution on compromised hosts.

T1218.011
Rundll32
MalwareEmissary

Variants of Emissary have used rundll32.exe in Registry values added to establish persistence.

T1218.011
Rundll32
MalwareMatryoshka

Matryoshka uses rundll32.exe in a Registry Run key value for execution as part of its persistence mechanism.

T1218.011
Rundll32
MalwareBad Rabbit

Bad Rabbit has used rundll32 to launch a malicious DLL as C:Windowsinfpub.dat.

T1218.011
Rundll32
MalwareEnvyScout

EnvyScout has the ability to proxy execution of malicious files with Rundll32.

T1218.011
Rundll32
MalwareGreyEnergy

GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM).

T1218.011
Rundll32
MalwarePrikormka

Prikormka uses rundll32.exe to load its DLL.

T1218.011
Rundll32
MalwareSquirrelwaffle

Squirrelwaffle has been executed using `rundll32.exe`.

T1218.011
Rundll32
MalwarePolyglotDuke

PolyglotDuke can be executed using rundll32.exe.

T1218.011
Rundll32
MalwareFlawedAmmyy

FlawedAmmyy has used `rundll32` for execution.

T1218.011
Rundll32
MalwareInvisiMole

InvisiMole has used rundll32.exe for execution.

T1218.011
Rundll32
MalwareRaspberry Robin

Raspberry Robin uses rundll32 execution without any command line parameters to contact command and control infrastructure, such as IP addresses associated with Tor nodes.

T1218.011
Rundll32
MalwareMispadu

Mispadu uses RunDLL32 for execution via its injector DLL.

T1218.011
Rundll32
MalwareIcedID

IcedID has used rundll32.exe to execute the IcedID loader.

T1218.011
Rundll32
MalwareRagnar Locker

Ragnar Locker has used rundll32.exe to execute components of VirtualBox.

T1218.011
Rundll32
MalwareFatDuke

FatDuke can execute via rundll32.

T1218.011
Rundll32
MalwareNotPetya

NotPetya uses rundll32.exe to install itself on remote systems when accessed via PsExec or wmic.

T1218.011
Rundll32
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using Rundll32.

T1218.011
Rundll32
MalwarePteranodon

Pteranodon executes functions using rundll32.exe.

T1218.011
Rundll32
MalwareCORESHELL

CORESHELL is installed via execution of rundll32 with an export named "init" or "InitW."

T1218.011
Rundll32
MalwareBisonal

Bisonal has used rundll32.exe to execute as part of the Registry Run key it adds: HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Run\”vert” = “rundll32.exe c:\windows\temp\pvcu.dll , Qszdez”.

T1218.011
Rundll32
MalwareMongall

Mongall can use `rundll32.exe` for execution.

T1218.011
Rundll32
MalwareSVCReady

SVCReady has used `rundll32.exe` for execution.

T1218.011
Rundll32
MalwareElise

After copying itself to a DLL file, a variant of Elise calls the DLL file using rundll32.exe.

T1218.011
Rundll32
MalwareUSBferry

USBferry can execute rundll32.exe in memory to avoid detection.

T1218.011
Rundll32
MalwareLatrodectus

Latrodectus can use rundll32.exe to execute downloaded DLLs.

T1218.011
Rundll32
MalwareBriba

Briba uses rundll32 within Registry Run Keys / Startup Folder entries to execute malicious DLLs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.