Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.010 Regsvr32 |
GroupKimsuky | Kimsuky has executed malware with |
| T1218.010 Regsvr32 |
GroupAPT32 | APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor. |
| T1218.010 Regsvr32 |
GroupLeviathan | Leviathan has used regsvr32 for execution. |
| T1218.010 Regsvr32 |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe. |
| T1218.010 Regsvr32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe. |
| T1218.010 Regsvr32 |
GroupTA551 | TA551 has used regsvr32.exe to load malicious DLLs. |
| T1218.010 Regsvr32 |
GroupDeep Panda | Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks. |
| T1218.010 Regsvr32 |
GroupCobalt Group | Cobalt Group has used regsvr32.exe to execute scripts. |
| T1218.010 Regsvr32 |
GroupInception | Inception has ensured persistence at system boot by setting the value |
| T1218.010 Regsvr32 |
GroupWIRTE | WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script. |
| T1218.010 Regsvr32 |
GroupAPT19 | APT19 used Regsvr32 to bypass application control techniques. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.