Threadlinqs IntelligenceStart free

ATT&CK techniqueStealth (formerly Defense Evasion)

T1218 System Binary Proxy Execution

Stealth (formerly Defense Evasion)Enterprise

As of 2026-10-05, T1218 (System Binary Proxy Execution) appears in 170 tracked threats, first reported 2026-02-02 and most recently 2026-09-30, with linked actors including APT28, APT43, Forest Blizzard; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
17029 critical, 124 high, 14 medium, 1 low
First seen
2026-02-02
Last seen
2026-09-30
Threat actors
61In the threats using it
Detection rules
120Blue tier and above

Data as of:

Activity timeline

T1218 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 54 reports, and 170 of the 170 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1218 System Binary Proxy Execution is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 170 of 2623 tracked threats (6.5%) to it; by severity that is 29 critical, 124 high, 14 medium, 1 low.

Threats that use T1218 most often also use T1027 Obfuscated Files or Information (141 threats), T1082 System Information Discovery (126 threats), T1059 Command and Scripting Interpreter (118 threats), T1071 Application Layer Protocol (116 threats), T1005 Data from Local System (106 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

61 tracked threat actors appear in the threats that use T1218; the most frequent are APT28 (7), APT43 (6), Forest Blizzard (6), Kimsuky (6), MuddyWater (5).

Mitigations

MITRE ATT&CK lists 6 mitigations for T1218.

Data sources

Telemetry that can reveal T1218, per MITRE ATT&CK.

  • Command — Command Execution
  • File — File Creation
  • Module — Module Load
  • Network Traffic — Network Connection Creation
  • Process — OS API Execution, Process Creation
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 170 tracked threats that use T1218.

Detection coverage

Threadlinqs maintains 120 detection rules mapped to T1218 (SPL 47, KQL 41, Sigma 32). Rule content is available to Blue tier accounts and above; this page shows counts only.

120 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1218.001 Compiled HTML File — 5 tracked threats
  • T1218.002 Control Panel — 2 tracked threats
  • T1218.003 CMSTP — 4 tracked threats
  • T1218.004 InstallUtil — 1 tracked threat
  • T1218.005 Mshta — 37 tracked threats
  • T1218.007 Msiexec — 37 tracked threats
  • T1218.008 Odbcconf — 0 tracked threats
  • T1218.009 Regsvcs/Regasm — 4 tracked threats
  • T1218.010 Regsvr32 — 14 tracked threats
  • T1218.011 Rundll32 — 30 tracked threats
  • T1218.012 Verclsid — 0 tracked threats
  • T1218.013 Mavinject — 0 tracked threats
  • T1218.014 MMC — 1 tracked threat
  • T1218.015 Electron Applications — 1 tracked threat