ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1218.011
Rundll32
MalwareEVILNUM

EVILNUM can execute commands and scripts through rundll32.

T1218.011
Rundll32
MalwareKONNI

KONNI has used Rundll32 to execute its loader for privilege escalation purposes.

T1218.011
Rundll32
Malwaregh0st RAT

A gh0st RAT variant has used rundll32 for execution.

T1218.011
Rundll32
MalwareJHUHUGIT

JHUHUGIT is executed using rundll32.exe.

T1218.011
Rundll32
MalwareAttor

Attor's installer plugin can schedule rundll32.exe to load the dispatcher.

T1218.011
Rundll32
MalwareMegaCortex

MegaCortex has used rundll32.exe to load a DLL for file encryption.

T1218.011
Rundll32
MalwareStreamEx

StreamEx uses rundll32 to call an exported function.

T1218.011
Rundll32
MalwareSDBbot

SDBbot has used rundll32.exe to execute DLLs.

T1218.011
Rundll32
MalwareMosquito

Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability.

T1218.011
Rundll32
MalwareRTM

RTM runs its core DLL file using rundll32.exe.

T1218.011
Rundll32
MalwareStrelaStealer

StrelaStealer DLL payloads have been executed via `rundll32.exe`.

T1218.011
Rundll32
MalwareSakula

Sakula calls cmd.exe to run various DLL files via rundll32.

T1218.011
Rundll32
MalwareSibot

Sibot has executed downloaded DLLs with rundll32.exe.

T1218.011
Rundll32
MalwareKapeka

Kapeka is a Windows DLL file executed via ordinal by `rundll32.exe`.

T1218.011
Rundll32
MalwareCobalt Strike

Cobalt Strike can use `rundll32.exe` to load DLL from the command line.

T1218.011
Rundll32
MalwareSUNBURST

SUNBURST used Rundll32 to execute payloads.

T1218.011
Rundll32
MalwareServHelper

ServHelper contains a module for downloading and executing DLLs that leverages rundll32.exe.

T1218.011
Rundll32
MalwareNativeZone

NativeZone has used rundll32 to execute a malicious DLL.

T1218.011
Rundll32
MalwareFunnyDream

FunnyDream can use `rundll32` for execution of its components.

T1218.011
Rundll32
MalwareKwampirs

Kwampirs uses rundll32.exe in a Registry value added to establish persistence.

T1218.011
Rundll32
MalwareBoomBox

BoomBox can use RunDLL32 for execution.

T1218.011
Rundll32
MalwareDEADEYE

DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`.

T1218.011
Rundll32
MalwareEgregor

Egregor has used rundll32 during execution.

T1218.011
Rundll32
MalwareFELIXROOT

FELIXROOT uses Rundll32 for executing the dropper program.

T1218.011
Rundll32
MalwareZxShell

ZxShell has used rundll32.exe to execute other DLLs and named pipes.

T1218.011
Rundll32
MalwareDDKONG

DDKONG uses Rundll32 to ensure only a single instance of itself is running at once.

T1218.011
Rundll32
MalwareWinnti for Windows

The Winnti for Windows installer loads a DLL using rundll32.

T1218.011
Rundll32
MalwareTroll Stealer

Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer.

T1218.011
Rundll32
MalwareHeyoka Backdoor

Heyoka Backdoor can use rundll32.exe to gain execution.

T1218.011
Rundll32
MalwareCozyCar

The CozyCar dropper copies the system file rundll32.exe to the install location for the malware, then uses the copy of rundll32.exe to load and execute the main CozyCar component.

T1218.011
Rundll32
MalwareQakBot

QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication.

T1218.011
Rundll32
MalwareComnie

Comnie uses Rundll32 to load a malicious DLL.

T1218.011
Rundll32
MalwareADVSTORESHELL

ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence.

T1218.011
Rundll32
MalwareHermeticWizard

HermeticWizard has the ability to create a new process using `rundll32`.

T1218.011
Rundll32
ToolPcShare

PcShare has used `rundll32.exe` for execution.

T1218.011
Rundll32
ToolKoadic

Koadic can use Rundll32 to execute additional payloads.

T1218.011
Rundll32
MalwareFlame

Rundll32.exe is used as a way of executing Flame at the command-line.

T1218.012
Verclsid
MalwareHancitor

Hancitor has used verclsid.exe to download and execute a malicious script.

T1218.013
Mavinject
MalwareTONESHELL

TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`.

T1218.014
MMC
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used Microsoft Management Console Snap-In Control files, or MSC files, executed via MMC to run follow-on PowerShell commands during RedDelta Modified PlugX Infection Chain Operations.

T1218.014
MMC
GroupMedusa Group

Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`.

T1218.015
Electron Applications
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged the 3CX application's electron framework to execute its malicious libraries under the official 3CX electron application.

T1218.015
Electron Applications
MalwareLumma Stealer

Lumma Stealer as leveraged Electron Applications to disable GPU sandboxing to avoid detection by security software.

T1219
Remote Access Tools
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY.

T1219
Remote Access Tools
CampaignNight Dragon

During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels.

T1219
Remote Access Tools
GroupBlackByte

BlackByte has used tools such as AnyDesk in victim environments.

T1219
Remote Access Tools
GroupTeamTNT

TeamTNT has established tmate sessions for C2 communications.

T1219
Remote Access Tools
GroupFIN7

FIN7 has utilized the remote management tool Atera to download malware to a compromised system.

T1219
Remote Access Tools
GroupSandworm Team

Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers.

T1219
Remote Access Tools
GroupAkira

Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.