Activity timeline
T1218 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 54 reports, and 170 of the 170 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1218 System Binary Proxy Execution is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 170 of 2623 tracked threats (6.5%) to it; by severity that is 29 critical, 124 high, 14 medium, 1 low.
Threats that use T1218 most often also use T1027 Obfuscated Files or Information (141 threats), T1082 System Information Discovery (126 threats), T1059 Command and Scripting Interpreter (118 threats), T1071 Application Layer Protocol (116 threats), T1005 Data from Local System (106 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
61 tracked threat actors appear in the threats that use T1218; the most frequent are APT28 (7), APT43 (6), Forest Blizzard (6), Kimsuky (6), MuddyWater (5).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1218.
Data sources
Telemetry that can reveal T1218, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation
- Module — Module Load
- Network Traffic — Network Connection Creation
- Process — OS API Execution, Process Creation
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 170 tracked threats that use T1218.
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)high
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvestershigh
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Techniquemedium
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…high
- Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE…high
- Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2high
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…critical
- MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…high
- SmartApeSG ClickFix Campaign Delivering Two-Stage RAT Infection via Fake CAPTCHA Social Engineering on…high
- WordlistLoader Delivering Amatera (ACR Stealer) via ClearFake FakeCaptcha Campaignshigh
- Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)high
- Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…medium
- CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for…
- Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…critical
- Google Blogger Automated Malware False Positive Locks Hundreds of Blogs — Platform-Wide Enforcement Error…low
- Ransomware Attack on QNET Disrupted by Microsoft Defender Automatic Device Isolation in 128 Seconds…high
- Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)high
- Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquattinghigh
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…critical
- Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…critical
- Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resiliencehigh
- Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC
- MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal…high
- AWS SSM Agent Abused as a Living-off-the-Land Remote Access Trojan via Hybrid-Activation Hijacking and…medium
- msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaShigh
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2high
Detection coverage
Threadlinqs maintains 120 detection rules mapped to T1218 (SPL 47, KQL 41, Sigma 32). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1218.001 Compiled HTML File — 5 tracked threats
- T1218.002 Control Panel — 2 tracked threats
- T1218.003 CMSTP — 4 tracked threats
- T1218.004 InstallUtil — 1 tracked threat
- T1218.005 Mshta — 37 tracked threats
- T1218.007 Msiexec — 37 tracked threats
- T1218.008 Odbcconf — 0 tracked threats
- T1218.009 Regsvcs/Regasm — 4 tracked threats
- T1218.010 Regsvr32 — 14 tracked threats
- T1218.011 Rundll32 — 30 tracked threats
- T1218.012 Verclsid — 0 tracked threats
- T1218.013 Mavinject — 0 tracked threats
- T1218.014 MMC — 1 tracked threat
- T1218.015 Electron Applications — 1 tracked threat