Activity timeline
T1218.011 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 13 reports, and 30 of the 30 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1218.011 Rundll32 is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1218 System Binary Proxy Execution. Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 1 critical, 23 high, 6 medium.
Threats that use T1218.011 most often also use T1059.001 PowerShell (23 threats), T1071.001 Web Protocols (23 threats), T1140 Deobfuscate/Decode Files or Information (22 threats), T1053.005 Scheduled Task (21 threats), T1027 Obfuscated Files or Information (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
16 tracked threat actors appear in the threats that use T1218.011; the most frequent are Armored Likho (3), APT43 (2), Kimsuky (2), Silver Fox APT (2), TA578 - G1038 (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1218.011.
Data sources
Telemetry that can reveal T1218.011, per MITRE ATT&CK.
- Command — Command Execution
- File — File Metadata
- Module — Module Load
- Process — Process Creation
Threat actors using it
Tracked threats
30 tracked threats use T1218.011.
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…critical
- DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patientshigh
- Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teamshigh
- Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Thefthigh
- GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruexmedium
- Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relayhigh
- UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malwarehigh
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)high
- Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets Portugalmedium
- COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware…high
- Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…medium
- DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaignsmedium
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo[.]org…high
- ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest…high
- Armored Likho APT (Eagle Werewolf) Deploys AI-Generated Loaders to Drop BusySnake Python Stealer Against…high
- Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK Abusehigh
- Armored Likho APT Deploys BusySnake Python Stealer with PyArmor Obfuscation Against Government and Power…high
- Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading…high
- Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote…high
- ClearFake EtherHiding on BNB Smart Chain Testnet — Smart Contract C2 Delivering SectopRAT + ACRStealer via…high
- SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon…high
- Silver Fox APT Tax-Themed Phishing — RustSL Loader, ValleyRAT & New ABCDoor Python Backdoorhigh
- Silver Fox APT Distributes ValleyRAT via Typosquatted Telegram Download Portalshigh
- Hive0163 Slopoly AI-Generated Backdoor and Interlock Ransomware Campaignhigh
- ValleyRAT via Fake Huorong AV Site — Silver Fox APT DLL Sideloading, Winos4.0 Framework, Encrypted Shellcode…high
- Screensaver (.SCR) Files Used as Initial Access Vectorhigh
- CVE-2026-2441 — Chrome Zero-Day Use-After-Free in CSS Actively Exploited in the Wildhigh
Detection coverage
Threadlinqs maintains 82 detection rules mapped to T1218.011 (SPL 35, KQL 23, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1218 System Binary Proxy Execution — 170 tracked threats at the technique level.