# T1218.010 Regsvr32

> As of 2026-10-05, T1218.010 (Regsvr32) appears in 14 tracked threats, first reported 2026-03-01 and most recently 2026-09-25, with linked actors including APT43, Kimsuky, Safepay; it most often appears alongside T1059.003 (Windows Command Shell).

- **Tracked threats:** 14 (3 critical, 10 high, 1 medium)
- **First seen:** 2026-03-01
- **Last seen:** 2026-09-25
- **Threat actors:** 9
- **Detection rules:** 26 (counts only; Blue tier and above)

## Key facts

- **ID:** T1218.010
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1218
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1218/010/

## Activity timeline

T1218.010 first appeared in tracked threats on 2026-03-01 and was most recently reported on 2026-09-25. The busiest month was 2026-07 with 6 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1218.010 Regsvr32 is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1218 System Binary Proxy Execution](https://intel.threadlinqs.com/technique/T1218). Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 3 critical, 10 high, 1 medium.

Threats that use T1218.010 most often also use [T1059.003 Windows Command Shell](https://intel.threadlinqs.com/technique/T1059.003) (11 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (11 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (10 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1218.010; the most frequent are [APT43](https://intel.threadlinqs.com/actor/APT43) (2), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (2), [Safepay](https://intel.threadlinqs.com/actor/Safepay) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1218.010.

- [M1050 Exploit Protection](https://attack.mitre.org/mitigations/M1050/)

## Data sources

Telemetry that can reveal T1218.010, per MITRE ATT&CK.

- Command — Command Execution
- Module — Module Load
- Network Traffic — Network Connection Creation
- Process — Process Creation

## Threat actors using it

- [APT43](https://intel.threadlinqs.com/actor/APT43) — 2
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 2
- [Safepay](https://intel.threadlinqs.com/actor/Safepay) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [Unnamed](https://intel.threadlinqs.com/actor/Unnamed) — 1

## Tracked threats

14 tracked threats use T1218.010.

- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [July 2026 Domestic APT Attack Trends (South Korea): LNK-Based Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2180) — high — 2026-08-28
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12
- [Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)](https://intel.threadlinqs.com/threat/TL-2026-1908) — critical — 2026-08-06
- [Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RAT](https://intel.threadlinqs.com/threat/TL-2026-1896) — critical — 2026-08-05
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…](https://intel.threadlinqs.com/threat/TL-2026-1664) — high — 2026-07-24
- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [Domestic APT Spear-Phishing Campaigns (May 2026) — LNK/HTA/CHM/JSE Loaders Deploying XenoRAT, Suspected…](https://intel.threadlinqs.com/threat/TL-2026-1229) — high — 2026-07-11
- [VEIL#DROP Campaign Uses Blogger-Hosted Stager to Deliver PureLogs Stealer](https://intel.threadlinqs.com/threat/TL-2026-1052) — medium — 2026-07-01
- [Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote…](https://intel.threadlinqs.com/threat/TL-2026-0626) — high — 2026-05-29
- [CPUID Supply Chain Compromise — Trojanized CPU-Z 2.19, HWMonitor 1.63, PerfMonitor 2, and powerMAX…](https://intel.threadlinqs.com/threat/TL-2026-0347) — critical — 2026-04-10
- [Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider…](https://intel.threadlinqs.com/threat/TL-2026-0161) — high — 2026-03-01

## Related CVEs

CVEs referenced by the tracked threats that use T1218.010, most frequent first.

- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291)
- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)

## Detection coverage

Threadlinqs maintains 26 detection rules mapped to T1218.010 (SPL 11, KQL 7, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

26 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1218 System Binary Proxy Execution](https://intel.threadlinqs.com/technique/T1218) — 170 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1218.010
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
