Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.005 Mshta |
GroupLazyScripter | LazyScripter has used `mshta.exe` to execute Koadic stagers. |
| T1218.005 Mshta |
GroupLazarus Group | Lazarus Group has used |
| T1218.005 Mshta |
GroupEarth Lusca | Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file. |
| T1218.005 Mshta |
GroupInception | Inception has used malicious HTA files to drop and execute malware. |
| T1218.007 Msiexec |
GroupAPT38 | APT38 has used `msiexec.exe` to execute malicious files. |
| T1218.007 Msiexec |
GroupMachete | |
| T1218.007 Msiexec |
GroupZIRCONIUM | ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files. |
| T1218.007 Msiexec |
GroupTA505 | TA505 has used |
| T1218.007 Msiexec |
GroupMolerats | Molerats has used msiexec.exe to execute an MSI payload. |
| T1218.007 Msiexec |
GroupRancor | Rancor has used |
| T1218.008 Odbcconf |
GroupCobalt Group | Cobalt Group has used |
| T1218.010 Regsvr32 |
GroupKimsuky | Kimsuky has executed malware with |
| T1218.010 Regsvr32 |
GroupAPT32 | APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor. |
| T1218.010 Regsvr32 |
GroupLeviathan | Leviathan has used regsvr32 for execution. |
| T1218.010 Regsvr32 |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe. |
| T1218.010 Regsvr32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe. |
| T1218.010 Regsvr32 |
GroupTA551 | TA551 has used regsvr32.exe to load malicious DLLs. |
| T1218.010 Regsvr32 |
GroupDeep Panda | Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks. |
| T1218.010 Regsvr32 |
GroupCobalt Group | Cobalt Group has used regsvr32.exe to execute scripts. |
| T1218.010 Regsvr32 |
GroupInception | Inception has ensured persistence at system boot by setting the value |
| T1218.010 Regsvr32 |
GroupWIRTE | WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script. |
| T1218.010 Regsvr32 |
GroupAPT19 | APT19 used Regsvr32 to bypass application control techniques. |
| T1218.011 Rundll32 |
GroupAPT38 | APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools. |
| T1218.011 Rundll32 |
GroupAPT3 | APT3 has a tool that can run DLLs. |
| T1218.011 Rundll32 |
GroupKimsuky | Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network. |
| T1218.011 Rundll32 |
GroupAPT41 | APT41 has used rundll32.exe to execute a loader. |
| T1218.011 Rundll32 |
GroupAPT32 | APT32 malware has used rundll32.exe to execute an initial infection process. |
| T1218.011 Rundll32 |
GroupHAFNIUM | HAFNIUM has used |
| T1218.011 Rundll32 |
GroupMuddyWater | MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll. |
| T1218.011 Rundll32 |
GroupGamaredon Group | Gamaredon Group malware has used rundll32 to launch additional malicious components. |
| T1218.011 Rundll32 |
GroupFIN7 | FIN7 has used `rundll32.exe` to execute malware on a compromised network. |
| T1218.011 Rundll32 |
GroupSandworm Team | Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe. |
| T1218.011 Rundll32 |
GroupUNC3886 | UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory. |
| T1218.011 Rundll32 |
GroupCarbanak | Carbanak installs VNC server software that executes through rundll32. |
| T1218.011 Rundll32 |
GroupAquatic Panda | Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary. |
| T1218.011 Rundll32 |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe. |
| T1218.011 Rundll32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe. |
| T1218.011 Rundll32 |
GroupTA505 | TA505 has leveraged |
| T1218.011 Rundll32 |
GroupRedCurl | RedCurl has used rundll32.exe to execute malicious files. |
| T1218.011 Rundll32 |
GroupTA551 | TA551 has used rundll32.exe to load malicious DLLs. |
| T1218.011 Rundll32 |
GroupLazyScripter | LazyScripter has used `rundll32.exe` to execute Koadic stagers. |
| T1218.011 Rundll32 |
GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| T1218.011 Rundll32 |
GroupLazarus Group | Lazarus Group has used rundll32 to execute malicious payloads on a compromised host. |
| T1218.011 Rundll32 |
GroupCopyKittens | CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode. |
| T1218.011 Rundll32 |
GroupWizard Spider | Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV. |
| T1218.011 Rundll32 |
GroupDaggerfly | Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary. |
| T1218.011 Rundll32 |
GroupMagic Hound | Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory. |
| T1218.011 Rundll32 |
GroupAPT19 | APT19 configured its payload to inject into the rundll32.exe. |
| T1218.014 MMC |
GroupMedusa Group | Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`. |
| T1219 Remote Access Tools |
GroupBlackByte | BlackByte has used tools such as AnyDesk in victim environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.