System Binary Proxy Execution

T1218

Technique with 14 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.

Similarly, on Linux systems adversaries may abuse trusted binaries such as split to proxy execution of malicious commands.

Detection rules323

Rules on DetectionCode tagged with T1218 or one of its sub-techniques.

Sigma221

RuleLevelLog sourceTechnique
HackTool - F-Secure C3 Load by Rundll32criticalwindows / process_creationT1218.011
Arbitrary File Download Via IMEWDBLD.EXEhighwindows / process_creationT1218
BaaUpdate.exe Suspicious DLL Loadhighwindows / image_loadT1218
Bad Opsec Defaults Sacrificial Processes With Improper Argumentshighwindows / process_creationT1218.011
Bypass UAC via CMSTPhighwindows / process_creationT1218.003
CMSTP App Paths Registry Key Modificationhighwindows / registry_eventT1218.003
CMSTP Execution Process Accesshighwindows / process_accessT1218.003
CMSTP Execution Process Creationhighwindows / process_creationT1218.003
CMSTP UAC Bypass via COM Object Accesshighwindows / process_creationT1218.003
CobaltStrike Load by Rundll32highwindows / process_creationT1218.011
Control Panel Itemshighwindows / process_creationT1218.002
Csc.EXE Execution Form Potentially Suspicious Parenthighwindows / process_creationT1218.005
Curl Download And Execute Combinationhighwindows / process_creationT1218
Devtoolslauncher.exe Executes Specified Binaryhighwindows / process_creationT1218
DLL Loaded From Suspicious Location Via Cmspt.EXEhighwindows / image_loadT1218.003

Splunk102

RuleTypeRiskData sourceTechnique
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLIAnomalyNULLCisco Network Visibility Module Flow DataT1218.005
Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload DownloadAnomalyNULLCisco Network Visibility Module Flow DataT1218.005
Cisco NVM - Suspicious Network Connection From Process With No ArgsAnomalyNULLCisco Network Visibility Module Flow DataT1218
CMLUA Or CMSTPLUA UAC BypassTTPNULLSysmon EventID 7T1218.003
Control Loading from World Writable DirectoryTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1218.002
Detect HTML Help RenamedHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1218.001
Detect HTML Help Spawn Child ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1218.001
Detect HTML Help URL in Command LineTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow DataT1218.001
Detect HTML Help Using InfoTech Storage HandlersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1218.001
Detect mshta inline hta executionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1218.005
Detect mshta renamedHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1218.005
Detect MSHTA Url in Command LineTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow DataT1218.005
Detect Regasm Spawning a ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1218.009
Detect Regasm with Network ConnectionTTPNULLSysmon EventID 3T1218.009
Detect Regasm with no Command Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1218.009

Sub-techniques14

IDNameExamples
T1218.001Compiled HTML File6
T1218.002Control Panel2
T1218.003CMSTP4
T1218.004InstallUtil6
T1218.005Mshta30
T1218.007Msiexec31
T1218.008Odbcconf3
T1218.009Regsvcs/Regasm1
T1218.010Regsvr3236
T1218.011Rundll32103
T1218.012Verclsid1
T1218.013Mavinject1
T1218.014MMC2
T1218.015Electron Applications2

Groups2

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

Groups2

Used byProcedure example
GroupLazarus Group

Lazarus Group lnk files used for persistence have abused the Windows Update Client (wuauclt.exe) to execute a malicious DLL.

GroupVolt Typhoon

Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks.

References3

  1. GTFO split Open source
    GTFOBins. (2020, November 13). split. Retrieved April 18, 2022.
  2. LOLBAS Project Open source
    Oddvar Moe et al. (2022, February). Living Off The Land Binaries, Scripts and Libraries. Retrieved March 7, 2022.
  3. split man page Open source
    Torbjorn Granlund, Richard M. Stallman. (2020, March null). split(1) — Linux manual page. Retrieved March 25, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.