Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.011 Rundll32 |
MalwareEVILNUM | EVILNUM can execute commands and scripts through rundll32. |
| T1218.011 Rundll32 |
MalwareKONNI | KONNI has used Rundll32 to execute its loader for privilege escalation purposes. |
| T1218.011 Rundll32 |
Malwaregh0st RAT | A gh0st RAT variant has used rundll32 for execution. |
| T1218.011 Rundll32 |
MalwareJHUHUGIT | JHUHUGIT is executed using rundll32.exe. |
| T1218.011 Rundll32 |
MalwareAttor | Attor's installer plugin can schedule rundll32.exe to load the dispatcher. |
| T1218.011 Rundll32 |
MalwareMegaCortex | MegaCortex has used |
| T1218.011 Rundll32 |
MalwareStreamEx | StreamEx uses rundll32 to call an exported function. |
| T1218.011 Rundll32 |
MalwareSDBbot | SDBbot has used rundll32.exe to execute DLLs. |
| T1218.011 Rundll32 |
MalwareMosquito | Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability. |
| T1218.011 Rundll32 |
MalwareRTM | RTM runs its core DLL file using rundll32.exe. |
| T1218.011 Rundll32 |
MalwareStrelaStealer | StrelaStealer DLL payloads have been executed via `rundll32.exe`. |
| T1218.011 Rundll32 |
MalwareSakula | Sakula calls cmd.exe to run various DLL files via rundll32. |
| T1218.011 Rundll32 |
MalwareSibot | Sibot has executed downloaded DLLs with |
| T1218.011 Rundll32 |
MalwareKapeka | Kapeka is a Windows DLL file executed via ordinal by `rundll32.exe`. |
| T1218.011 Rundll32 |
MalwareCobalt Strike | Cobalt Strike can use `rundll32.exe` to load DLL from the command line. |
| T1218.011 Rundll32 |
MalwareSUNBURST | SUNBURST used Rundll32 to execute payloads. |
| T1218.011 Rundll32 |
MalwareServHelper | ServHelper contains a module for downloading and executing DLLs that leverages |
| T1218.011 Rundll32 |
MalwareNativeZone | NativeZone has used rundll32 to execute a malicious DLL. |
| T1218.011 Rundll32 |
MalwareFunnyDream | FunnyDream can use `rundll32` for execution of its components. |
| T1218.011 Rundll32 |
MalwareKwampirs | Kwampirs uses rundll32.exe in a Registry value added to establish persistence. |
| T1218.011 Rundll32 |
MalwareBoomBox | BoomBox can use RunDLL32 for execution. |
| T1218.011 Rundll32 |
MalwareDEADEYE | DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`. |
| T1218.011 Rundll32 |
MalwareEgregor | Egregor has used rundll32 during execution. |
| T1218.011 Rundll32 |
MalwareFELIXROOT | FELIXROOT uses Rundll32 for executing the dropper program. |
| T1218.011 Rundll32 |
MalwareZxShell | ZxShell has used rundll32.exe to execute other DLLs and named pipes. |
| T1218.011 Rundll32 |
MalwareDDKONG | DDKONG uses Rundll32 to ensure only a single instance of itself is running at once. |
| T1218.011 Rundll32 |
MalwareWinnti for Windows | The Winnti for Windows installer loads a DLL using rundll32. |
| T1218.011 Rundll32 |
MalwareTroll Stealer | Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer. |
| T1218.011 Rundll32 |
MalwareHeyoka Backdoor | Heyoka Backdoor can use rundll32.exe to gain execution. |
| T1218.011 Rundll32 |
MalwareCozyCar | The CozyCar dropper copies the system file rundll32.exe to the install location for the malware, then uses the copy of rundll32.exe to load and execute the main CozyCar component. |
| T1218.011 Rundll32 |
MalwareQakBot | QakBot has used Rundll32.exe to drop malicious DLLs including Brute Ratel C4 and to enable C2 communication. |
| T1218.011 Rundll32 |
MalwareComnie | Comnie uses Rundll32 to load a malicious DLL. |
| T1218.011 Rundll32 |
MalwareADVSTORESHELL | ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence. |
| T1218.011 Rundll32 |
MalwareHermeticWizard | HermeticWizard has the ability to create a new process using `rundll32`. |
| T1218.011 Rundll32 |
ToolPcShare | PcShare has used `rundll32.exe` for execution. |
| T1218.011 Rundll32 |
ToolKoadic | Koadic can use Rundll32 to execute additional payloads. |
| T1218.011 Rundll32 |
MalwareFlame | Rundll32.exe is used as a way of executing Flame at the command-line. |
| T1218.012 Verclsid |
MalwareHancitor | Hancitor has used verclsid.exe to download and execute a malicious script. |
| T1218.013 Mavinject |
MalwareTONESHELL | TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`. |
| T1218.014 MMC |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used Microsoft Management Console Snap-In Control files, or MSC files, executed via MMC to run follow-on PowerShell commands during RedDelta Modified PlugX Infection Chain Operations. |
| T1218.014 MMC |
GroupMedusa Group | Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`. |
| T1218.015 Electron Applications |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged the 3CX application's electron framework to execute its malicious libraries under the official 3CX electron application. |
| T1218.015 Electron Applications |
MalwareLumma Stealer | Lumma Stealer as leveraged Electron Applications to disable GPU sandboxing to avoid detection by security software. |
| T1219 Remote Access Tools |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY. |
| T1219 Remote Access Tools |
CampaignNight Dragon | During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels. |
| T1219 Remote Access Tools |
GroupBlackByte | BlackByte has used tools such as AnyDesk in victim environments. |
| T1219 Remote Access Tools |
GroupTeamTNT | TeamTNT has established tmate sessions for C2 communications. |
| T1219 Remote Access Tools |
GroupFIN7 | FIN7 has utilized the remote management tool Atera to download malware to a compromised system. |
| T1219 Remote Access Tools |
GroupSandworm Team | Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers. |
| T1219 Remote Access Tools |
GroupAkira | Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.