ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1218.011×

69 examples

TechniqueUsed byProcedure example
T1218.011
Rundll32
MalwarePowerDuke

PowerDuke uses rundll32.exe to load.

T1218.011
Rundll32
MalwareBLINDINGCAN

BLINDINGCAN has used Rundll32 to load a malicious DLL.

T1218.011
Rundll32
MalwareNinja

Ninja loader components can be executed through rundll32.exe.

T1218.011
Rundll32
MalwareBumblebee

Bumblebee has used `rundll32` for execution of the loader component.

T1218.011
Rundll32
MalwareNOKKI

NOKKI has used rundll32 for execution.

T1218.011
Rundll32
MalwareBackdoor.Oldrea

Backdoor.Oldrea can use rundll32 for execution on compromised hosts.

T1218.011
Rundll32
MalwareEmissary

Variants of Emissary have used rundll32.exe in Registry values added to establish persistence.

T1218.011
Rundll32
MalwareMatryoshka

Matryoshka uses rundll32.exe in a Registry Run key value for execution as part of its persistence mechanism.

T1218.011
Rundll32
MalwareBad Rabbit

Bad Rabbit has used rundll32 to launch a malicious DLL as C:Windowsinfpub.dat.

T1218.011
Rundll32
MalwareEnvyScout

EnvyScout has the ability to proxy execution of malicious files with Rundll32.

T1218.011
Rundll32
MalwareGreyEnergy

GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM).

T1218.011
Rundll32
MalwarePrikormka

Prikormka uses rundll32.exe to load its DLL.

T1218.011
Rundll32
MalwareSquirrelwaffle

Squirrelwaffle has been executed using `rundll32.exe`.

T1218.011
Rundll32
MalwarePolyglotDuke

PolyglotDuke can be executed using rundll32.exe.

T1218.011
Rundll32
MalwareFlawedAmmyy

FlawedAmmyy has used `rundll32` for execution.

T1218.011
Rundll32
MalwareInvisiMole

InvisiMole has used rundll32.exe for execution.

T1218.011
Rundll32
MalwareRaspberry Robin

Raspberry Robin uses rundll32 execution without any command line parameters to contact command and control infrastructure, such as IP addresses associated with Tor nodes.

T1218.011
Rundll32
MalwareMispadu

Mispadu uses RunDLL32 for execution via its injector DLL.

T1218.011
Rundll32
MalwareIcedID

IcedID has used rundll32.exe to execute the IcedID loader.

T1218.011
Rundll32
MalwareRagnar Locker

Ragnar Locker has used rundll32.exe to execute components of VirtualBox.

T1218.011
Rundll32
MalwareFatDuke

FatDuke can execute via rundll32.

T1218.011
Rundll32
MalwareNotPetya

NotPetya uses rundll32.exe to install itself on remote systems when accessed via PsExec or wmic.

T1218.011
Rundll32
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using Rundll32.

T1218.011
Rundll32
MalwarePteranodon

Pteranodon executes functions using rundll32.exe.

T1218.011
Rundll32
MalwareCORESHELL

CORESHELL is installed via execution of rundll32 with an export named "init" or "InitW."

T1218.011
Rundll32
MalwareBisonal

Bisonal has used rundll32.exe to execute as part of the Registry Run key it adds: HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Run\”vert” = “rundll32.exe c:\windows\temp\pvcu.dll , Qszdez”.

T1218.011
Rundll32
MalwareMongall

Mongall can use `rundll32.exe` for execution.

T1218.011
Rundll32
MalwareSVCReady

SVCReady has used `rundll32.exe` for execution.

T1218.011
Rundll32
MalwareElise

After copying itself to a DLL file, a variant of Elise calls the DLL file using rundll32.exe.

T1218.011
Rundll32
MalwareUSBferry

USBferry can execute rundll32.exe in memory to avoid detection.

T1218.011
Rundll32
MalwareLatrodectus

Latrodectus can use rundll32.exe to execute downloaded DLLs.

T1218.011
Rundll32
MalwareBriba

Briba uses rundll32 within Registry Run Keys / Startup Folder entries to execute malicious DLLs.

T1218.011
Rundll32
MalwareEVILNUM

EVILNUM can execute commands and scripts through rundll32.

T1218.011
Rundll32
MalwareKONNI

KONNI has used Rundll32 to execute its loader for privilege escalation purposes.

T1218.011
Rundll32
Malwaregh0st RAT

A gh0st RAT variant has used rundll32 for execution.

T1218.011
Rundll32
MalwareJHUHUGIT

JHUHUGIT is executed using rundll32.exe.

T1218.011
Rundll32
MalwareAttor

Attor's installer plugin can schedule rundll32.exe to load the dispatcher.

T1218.011
Rundll32
MalwareMegaCortex

MegaCortex has used rundll32.exe to load a DLL for file encryption.

T1218.011
Rundll32
MalwareStreamEx

StreamEx uses rundll32 to call an exported function.

T1218.011
Rundll32
MalwareSDBbot

SDBbot has used rundll32.exe to execute DLLs.

T1218.011
Rundll32
MalwareMosquito

Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability.

T1218.011
Rundll32
MalwareRTM

RTM runs its core DLL file using rundll32.exe.

T1218.011
Rundll32
MalwareStrelaStealer

StrelaStealer DLL payloads have been executed via `rundll32.exe`.

T1218.011
Rundll32
MalwareSakula

Sakula calls cmd.exe to run various DLL files via rundll32.

T1218.011
Rundll32
MalwareSibot

Sibot has executed downloaded DLLs with rundll32.exe.

T1218.011
Rundll32
MalwareKapeka

Kapeka is a Windows DLL file executed via ordinal by `rundll32.exe`.

T1218.011
Rundll32
MalwareCobalt Strike

Cobalt Strike can use `rundll32.exe` to load DLL from the command line.

T1218.011
Rundll32
MalwareSUNBURST

SUNBURST used Rundll32 to execute payloads.

T1218.011
Rundll32
MalwareServHelper

ServHelper contains a module for downloading and executing DLLs that leverages rundll32.exe.

T1218.011
Rundll32
MalwareNativeZone

NativeZone has used rundll32 to execute a malicious DLL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.