Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.011 Rundll32 |
GroupFIN7 | FIN7 has used `rundll32.exe` to execute malware on a compromised network. |
| T1218.011 Rundll32 |
GroupSandworm Team | Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe. |
| T1218.011 Rundll32 |
GroupUNC3886 | UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory. |
| T1218.011 Rundll32 |
GroupCarbanak | Carbanak installs VNC server software that executes through rundll32. |
| T1218.011 Rundll32 |
GroupAquatic Panda | Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary. |
| T1218.011 Rundll32 |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe. |
| T1218.011 Rundll32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe. |
| T1218.011 Rundll32 |
GroupTA505 | TA505 has leveraged |
| T1218.011 Rundll32 |
GroupRedCurl | RedCurl has used rundll32.exe to execute malicious files. |
| T1218.011 Rundll32 |
GroupTA551 | TA551 has used rundll32.exe to load malicious DLLs. |
| T1218.011 Rundll32 |
GroupLazyScripter | LazyScripter has used `rundll32.exe` to execute Koadic stagers. |
| T1218.011 Rundll32 |
GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| T1218.011 Rundll32 |
GroupLazarus Group | Lazarus Group has used rundll32 to execute malicious payloads on a compromised host. |
| T1218.011 Rundll32 |
GroupCopyKittens | CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode. |
| T1218.011 Rundll32 |
GroupWizard Spider | Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV. |
| T1218.011 Rundll32 |
GroupDaggerfly | Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary. |
| T1218.011 Rundll32 |
GroupMagic Hound | Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory. |
| T1218.011 Rundll32 |
GroupAPT19 | APT19 configured its payload to inject into the rundll32.exe. |
| T1218.011 Rundll32 |
MalwarePowerDuke | PowerDuke uses rundll32.exe to load. |
| T1218.011 Rundll32 |
MalwareBLINDINGCAN | BLINDINGCAN has used Rundll32 to load a malicious DLL. |
| T1218.011 Rundll32 |
MalwareNinja | Ninja loader components can be executed through rundll32.exe. |
| T1218.011 Rundll32 |
MalwareBumblebee | Bumblebee has used `rundll32` for execution of the loader component. |
| T1218.011 Rundll32 |
MalwareNOKKI | NOKKI has used rundll32 for execution. |
| T1218.011 Rundll32 |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can use rundll32 for execution on compromised hosts. |
| T1218.011 Rundll32 |
MalwareEmissary | Variants of Emissary have used rundll32.exe in Registry values added to establish persistence. |
| T1218.011 Rundll32 |
MalwareMatryoshka | Matryoshka uses rundll32.exe in a Registry Run key value for execution as part of its persistence mechanism. |
| T1218.011 Rundll32 |
MalwareBad Rabbit | Bad Rabbit has used rundll32 to launch a malicious DLL as |
| T1218.011 Rundll32 |
MalwareEnvyScout | EnvyScout has the ability to proxy execution of malicious files with Rundll32. |
| T1218.011 Rundll32 |
MalwareGreyEnergy | GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM). |
| T1218.011 Rundll32 |
MalwarePrikormka | Prikormka uses rundll32.exe to load its DLL. |
| T1218.011 Rundll32 |
MalwareSquirrelwaffle | Squirrelwaffle has been executed using `rundll32.exe`. |
| T1218.011 Rundll32 |
MalwarePolyglotDuke | PolyglotDuke can be executed using rundll32.exe. |
| T1218.011 Rundll32 |
MalwareFlawedAmmyy | FlawedAmmyy has used `rundll32` for execution. |
| T1218.011 Rundll32 |
MalwareInvisiMole | InvisiMole has used rundll32.exe for execution. |
| T1218.011 Rundll32 |
MalwareRaspberry Robin | Raspberry Robin uses rundll32 execution without any command line parameters to contact command and control infrastructure, such as IP addresses associated with Tor nodes. |
| T1218.011 Rundll32 |
MalwareMispadu | Mispadu uses RunDLL32 for execution via its injector DLL. |
| T1218.011 Rundll32 |
MalwareIcedID | |
| T1218.011 Rundll32 |
MalwareRagnar Locker | Ragnar Locker has used rundll32.exe to execute components of VirtualBox. |
| T1218.011 Rundll32 |
MalwareFatDuke | FatDuke can execute via rundll32. |
| T1218.011 Rundll32 |
MalwareNotPetya | NotPetya uses |
| T1218.011 Rundll32 |
MalwarePUNCHBUGGY | PUNCHBUGGY can load a DLL using Rundll32. |
| T1218.011 Rundll32 |
MalwarePteranodon | Pteranodon executes functions using rundll32.exe. |
| T1218.011 Rundll32 |
MalwareCORESHELL | CORESHELL is installed via execution of rundll32 with an export named "init" or "InitW." |
| T1218.011 Rundll32 |
MalwareBisonal | Bisonal has used rundll32.exe to execute as part of the Registry Run key it adds: |
| T1218.011 Rundll32 |
MalwareMongall | Mongall can use `rundll32.exe` for execution. |
| T1218.011 Rundll32 |
MalwareSVCReady | SVCReady has used `rundll32.exe` for execution. |
| T1218.011 Rundll32 |
MalwareElise | After copying itself to a DLL file, a variant of Elise calls the DLL file using rundll32.exe. |
| T1218.011 Rundll32 |
MalwareUSBferry | USBferry can execute rundll32.exe in memory to avoid detection. |
| T1218.011 Rundll32 |
MalwareLatrodectus | Latrodectus can use rundll32.exe to execute downloaded DLLs. |
| T1218.011 Rundll32 |
MalwareBriba | Briba uses rundll32 within Registry Run Keys / Startup Folder entries to execute malicious DLLs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.