ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1218.011×

26 examples

TechniqueUsed byProcedure example
T1218.011
Rundll32
GroupAPT38

APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools.

T1218.011
Rundll32
GroupAPT3

APT3 has a tool that can run DLLs.

T1218.011
Rundll32
GroupKimsuky

Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network.

T1218.011
Rundll32
GroupAPT41

APT41 has used rundll32.exe to execute a loader.

T1218.011
Rundll32
GroupAPT32

APT32 malware has used rundll32.exe to execute an initial infection process.

T1218.011
Rundll32
GroupHAFNIUM

HAFNIUM has used rundll32 to load malicious DLLs.

T1218.011
Rundll32
GroupMuddyWater

MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll.

T1218.011
Rundll32
GroupGamaredon Group

Gamaredon Group malware has used rundll32 to launch additional malicious components.

T1218.011
Rundll32
GroupFIN7

FIN7 has used `rundll32.exe` to execute malware on a compromised network.

T1218.011
Rundll32
GroupSandworm Team

Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe.

T1218.011
Rundll32
GroupUNC3886

UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory.

T1218.011
Rundll32
GroupCarbanak

Carbanak installs VNC server software that executes through rundll32.

T1218.011
Rundll32
GroupAquatic Panda

Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary.

T1218.011
Rundll32
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.

T1218.011
Rundll32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe.

T1218.011
Rundll32
GroupTA505

TA505 has leveraged rundll32.exe to execute malicious DLLs.

T1218.011
Rundll32
GroupRedCurl

RedCurl has used rundll32.exe to execute malicious files.

T1218.011
Rundll32
GroupTA551

TA551 has used rundll32.exe to load malicious DLLs.

T1218.011
Rundll32
GroupLazyScripter

LazyScripter has used `rundll32.exe` to execute Koadic stagers.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1218.011
Rundll32
GroupLazarus Group

Lazarus Group has used rundll32 to execute malicious payloads on a compromised host.

T1218.011
Rundll32
GroupCopyKittens

CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode.

T1218.011
Rundll32
GroupWizard Spider

Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV.

T1218.011
Rundll32
GroupDaggerfly

Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary.

T1218.011
Rundll32
GroupMagic Hound

Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory.

T1218.011
Rundll32
GroupAPT19

APT19 configured its payload to inject into the rundll32.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.