ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1218.005
Mshta
GroupLazyScripter

LazyScripter has used `mshta.exe` to execute Koadic stagers.

T1218.005
Mshta
GroupLazarus Group

Lazarus Group has used mshta.exe to execute HTML pages downloaded by initial access documents.

T1218.005
Mshta
GroupEarth Lusca

Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file.

T1218.005
Mshta
GroupInception

Inception has used malicious HTA files to drop and execute malware.

T1218.007
Msiexec
GroupAPT38

APT38 has used `msiexec.exe` to execute malicious files.

T1218.007
Msiexec
GroupMachete

Machete has used msiexec to install the Machete malware.

T1218.007
Msiexec
GroupZIRCONIUM

ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files.

T1218.007
Msiexec
GroupTA505

TA505 has used msiexec to download and execute malicious Windows Installer files.

T1218.007
Msiexec
GroupMolerats

Molerats has used msiexec.exe to execute an MSI payload.

T1218.007
Msiexec
GroupRancor

Rancor has used msiexec to download and execute malicious installer files over HTTP.

T1218.008
Odbcconf
GroupCobalt Group

Cobalt Group has used odbcconf to proxy the execution of malicious DLL files.

T1218.010
Regsvr32
GroupKimsuky

Kimsuky has executed malware with regsvr32s.

T1218.010
Regsvr32
GroupAPT32

APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor.

T1218.010
Regsvr32
GroupLeviathan

Leviathan has used regsvr32 for execution.

T1218.010
Regsvr32
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe.

T1218.010
Regsvr32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe.

T1218.010
Regsvr32
GroupTA551

TA551 has used regsvr32.exe to load malicious DLLs.

T1218.010
Regsvr32
GroupDeep Panda

Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks.

T1218.010
Regsvr32
GroupCobalt Group

Cobalt Group has used regsvr32.exe to execute scripts.

T1218.010
Regsvr32
GroupInception

Inception has ensured persistence at system boot by setting the value regsvr32 %path%\ctfmonrn.dll /s.

T1218.010
Regsvr32
GroupWIRTE

WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script.

T1218.010
Regsvr32
GroupAPT19

APT19 used Regsvr32 to bypass application control techniques.

T1218.011
Rundll32
GroupAPT38

APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools.

T1218.011
Rundll32
GroupAPT3

APT3 has a tool that can run DLLs.

T1218.011
Rundll32
GroupKimsuky

Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network.

T1218.011
Rundll32
GroupAPT41

APT41 has used rundll32.exe to execute a loader.

T1218.011
Rundll32
GroupAPT32

APT32 malware has used rundll32.exe to execute an initial infection process.

T1218.011
Rundll32
GroupHAFNIUM

HAFNIUM has used rundll32 to load malicious DLLs.

T1218.011
Rundll32
GroupMuddyWater

MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll.

T1218.011
Rundll32
GroupGamaredon Group

Gamaredon Group malware has used rundll32 to launch additional malicious components.

T1218.011
Rundll32
GroupFIN7

FIN7 has used `rundll32.exe` to execute malware on a compromised network.

T1218.011
Rundll32
GroupSandworm Team

Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe.

T1218.011
Rundll32
GroupUNC3886

UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory.

T1218.011
Rundll32
GroupCarbanak

Carbanak installs VNC server software that executes through rundll32.

T1218.011
Rundll32
GroupAquatic Panda

Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary.

T1218.011
Rundll32
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.

T1218.011
Rundll32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe.

T1218.011
Rundll32
GroupTA505

TA505 has leveraged rundll32.exe to execute malicious DLLs.

T1218.011
Rundll32
GroupRedCurl

RedCurl has used rundll32.exe to execute malicious files.

T1218.011
Rundll32
GroupTA551

TA551 has used rundll32.exe to load malicious DLLs.

T1218.011
Rundll32
GroupLazyScripter

LazyScripter has used `rundll32.exe` to execute Koadic stagers.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1218.011
Rundll32
GroupLazarus Group

Lazarus Group has used rundll32 to execute malicious payloads on a compromised host.

T1218.011
Rundll32
GroupCopyKittens

CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode.

T1218.011
Rundll32
GroupWizard Spider

Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV.

T1218.011
Rundll32
GroupDaggerfly

Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary.

T1218.011
Rundll32
GroupMagic Hound

Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory.

T1218.011
Rundll32
GroupAPT19

APT19 configured its payload to inject into the rundll32.exe.

T1218.014
MMC
GroupMedusa Group

Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`.

T1219
Remote Access Tools
GroupBlackByte

BlackByte has used tools such as AnyDesk in victim environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.