1200KM / simulation
T1218.011 Rundll32 — Attack Simulation
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: rundll32.exe {DLLname, DLLfunction}). Rundll32.exe can also be used to execute…
Technique description
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: rundll32.exe {DLLname, DLLfunction}). Rundll32.exe can also be used to execute…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Execution of HTA and VBS Files using Rundll32 and URL.dll
Procedure 22cfde89-befe-4e15-9753-47306b37a6e3; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Running DLL with .init extension and function
Procedure 2d5029f0-ae20-446f-8811-e7511b58e8b6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 execute VBscript command using Ordinal number
Procedure 32d1cf1b-cbc2-4c09-8d05-07ec5c83a821; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 syssetup.dll Execution
Procedure 41fa324a-3946-401e-bbdd-d7991c628125; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 execute JavaScript Remote Payload With GetObject
Procedure 57ba4ce9-ee7a-4f27-9928-3c70c489b59d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Rundll32 ieadvpack.dll Execution
Procedure 5e46a58e-cbf6-45ef-a289-ed7754603df9; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 execute VBscript command
Procedure 638730e7-7aed-43dc-bf8c-8117f805f5bb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 setupapi.dll Execution
Procedure 71d771cd-d6b3-4f34-bc76-a63d47a10b19; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 with desk.cpl
Procedure 83a95136-a496-423c-81d3-1c6750133917; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Rundll32 execute payload by calling RouteTheCall
Procedure 8a7f56ee-10e7-444c-a139-0109438288eb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Launches an executable using Rundll32 and pcwutl.dll
Procedure 9f5d081a-ee5a-42f9-a04e-b7bdc487e676; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 with Ordinal Value
Procedure 9fd5a74b-ba89-482a-8a3e-a5feaa3697b0; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Execution of non-dll using rundll32.exe
Procedure ae3a8605-b26e-457c-b6b3-2702fd335bac; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 advpack.dll Execution
Procedure d91cae26-7fc1-457b-a854-34c8aad48c89; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 with Control_RunDLL
Procedure e4c04b6f-c492-4782-82c7-3bf75eb8077e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Rundll32 execute command via FileProtocolHandler
Procedure f3ad3c5b-1db1-45c1-81bf-d3370ebab6c8; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Carbanak · G0008
- APT3 · G0022
- Lazarus Group · G0032
- Sandworm Team · G0034
- FIN7 · G0046
- Gamaredon Group · G0047
- APT32 · G0050
- CopyKittens · G0052
- Magic Hound · G0059
- MuddyWater · G0069
- APT19 · G0073
- APT38 · G0082
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- HAFNIUM · G0125
- TA551 · G0127
- LazyScripter · G0140
- Aquatic Panda · G0143
- Daggerfly · G1034
- RedCurl · G1039
- UNC3886 · G1048
- Storm-0501 · G1053
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.