ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1218.010×

11 examples

TechniqueUsed byProcedure example
T1218.010
Regsvr32
GroupKimsuky

Kimsuky has executed malware with regsvr32s.

T1218.010
Regsvr32
GroupAPT32

APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor.

T1218.010
Regsvr32
GroupLeviathan

Leviathan has used regsvr32 for execution.

T1218.010
Regsvr32
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe.

T1218.010
Regsvr32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe.

T1218.010
Regsvr32
GroupTA551

TA551 has used regsvr32.exe to load malicious DLLs.

T1218.010
Regsvr32
GroupDeep Panda

Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks.

T1218.010
Regsvr32
GroupCobalt Group

Cobalt Group has used regsvr32.exe to execute scripts.

T1218.010
Regsvr32
GroupInception

Inception has ensured persistence at system boot by setting the value regsvr32 %path%\ctfmonrn.dll /s.

T1218.010
Regsvr32
GroupWIRTE

WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script.

T1218.010
Regsvr32
GroupAPT19

APT19 used Regsvr32 to bypass application control techniques.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.