# T1218.011 Rundll32

> As of 2026-10-05, T1218.011 (Rundll32) appears in 30 tracked threats, first reported 2026-02-16 and most recently 2026-09-29, with linked actors including Armored Likho, APT43, Kimsuky; it most often appears alongside T1059.001 (PowerShell).

- **Tracked threats:** 30 (1 critical, 23 high, 6 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-29
- **Threat actors:** 16
- **Detection rules:** 82 (counts only; Blue tier and above)

## Key facts

- **ID:** T1218.011
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1218
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1218/011/

## Activity timeline

T1218.011 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 13 reports, and 30 of the 30 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1218.011 Rundll32 is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1218 System Binary Proxy Execution](https://intel.threadlinqs.com/technique/T1218). Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 1 critical, 23 high, 6 medium.

Threats that use T1218.011 most often also use [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (23 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (23 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (22 threats), [T1053.005 Scheduled Task](https://intel.threadlinqs.com/technique/T1053.005) (21 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

16 tracked threat actors appear in the threats that use T1218.011; the most frequent are [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) (3), [APT43](https://intel.threadlinqs.com/actor/APT43) (2), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (2), [Silver Fox APT](https://intel.threadlinqs.com/actor/Silver%20Fox%20APT) (2), [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1218.011.

- [M1050 Exploit Protection](https://attack.mitre.org/mitigations/M1050/)

## Data sources

Telemetry that can reveal T1218.011, per MITRE ATT&CK.

- Command — Command Execution
- File — File Metadata
- Module — Module Load
- Process — Process Creation

## Threat actors using it

- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 3
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 2
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 2
- [Silver Fox APT](https://intel.threadlinqs.com/actor/Silver%20Fox%20APT) — 2
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 2
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 2
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [Interlock](https://intel.threadlinqs.com/actor/Interlock) — 1
- [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) — 1

## Tracked threats

30 tracked threats use T1218.011.

- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systems](https://intel.threadlinqs.com/threat/TL-2026-2612) — medium — 2026-09-22
- [ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…](https://intel.threadlinqs.com/threat/TL-2026-2387) — critical — 2026-09-08
- [DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients](https://intel.threadlinqs.com/threat/TL-2026-2328) — high — 2026-09-04
- [Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teams](https://intel.threadlinqs.com/threat/TL-2026-2302) — high — 2026-09-02
- [Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft](https://intel.threadlinqs.com/threat/TL-2026-2229) — high — 2026-08-28
- [GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruex](https://intel.threadlinqs.com/threat/TL-2026-2059) — medium — 2026-08-18
- [Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay](https://intel.threadlinqs.com/threat/TL-2026-2053) — high — 2026-08-17
- [UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malware](https://intel.threadlinqs.com/threat/TL-2026-1657) — high — 2026-07-23
- [TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)](https://intel.threadlinqs.com/threat/TL-2026-1651) — high — 2026-07-23
- [Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets Portugal](https://intel.threadlinqs.com/threat/TL-2026-1619) — medium — 2026-07-22
- [COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware…](https://intel.threadlinqs.com/threat/TL-2026-1510) — high — 2026-07-19
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1485) — medium — 2026-07-18
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo\[.\]org…](https://intel.threadlinqs.com/threat/TL-2026-1483) — high — 2026-07-18
- [ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest…](https://intel.threadlinqs.com/threat/TL-2026-1444) — high — 2026-07-17
- [Armored Likho APT (Eagle Werewolf) Deploys AI-Generated Loaders to Drop BusySnake Python Stealer Against…](https://intel.threadlinqs.com/threat/TL-2026-1260) — high — 2026-07-13
- [Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK Abuse](https://intel.threadlinqs.com/threat/TL-2026-1108) — high — 2026-07-03
- [Armored Likho APT Deploys BusySnake Python Stealer with PyArmor Obfuscation Against Government and Power…](https://intel.threadlinqs.com/threat/TL-2026-1097) — high — 2026-07-03
- [Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading…](https://intel.threadlinqs.com/threat/TL-2026-1038) — high — 2026-07-01
- [Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote…](https://intel.threadlinqs.com/threat/TL-2026-0626) — high — 2026-05-29
- [ClearFake EtherHiding on BNB Smart Chain Testnet — Smart Contract C2 Delivering SectopRAT + ACRStealer via…](https://intel.threadlinqs.com/threat/TL-2026-0592) — high — 2026-05-26
- [SHADOW-EARTH-053 — China-Aligned Cyberespionage Campaign Exploiting Microsoft Exchange (ProxyLogon…](https://intel.threadlinqs.com/threat/TL-2026-0493) — high — 2026-05-11
- [Silver Fox APT Tax-Themed Phishing — RustSL Loader, ValleyRAT & New ABCDoor Python Backdoor](https://intel.threadlinqs.com/threat/TL-2026-0443) — high — 2026-04-30
- [Silver Fox APT Distributes ValleyRAT via Typosquatted Telegram Download Portals](https://intel.threadlinqs.com/threat/TL-2026-0239) — high — 2026-03-17
- [Hive0163 Slopoly AI-Generated Backdoor and Interlock Ransomware Campaign](https://intel.threadlinqs.com/threat/TL-2026-0227) — high — 2026-03-14
- [ValleyRAT via Fake Huorong AV Site — Silver Fox APT DLL Sideloading, Winos4.0 Framework, Encrypted Shellcode…](https://intel.threadlinqs.com/threat/TL-2026-0138) — high — 2026-02-24
- [Screensaver (.SCR) Files Used as Initial Access Vector](https://intel.threadlinqs.com/threat/TL-2026-0104) — high — 2026-02-16
- [CVE-2026-2441 — Chrome Zero-Day Use-After-Free in CSS Actively Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-0088) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1218.011, most frequent first.

- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-56383](https://intel.threadlinqs.com/cve/CVE-2025-56383)
- [CVE-2026-2441](https://intel.threadlinqs.com/cve/CVE-2026-2441)

## Detection coverage

Threadlinqs maintains 82 detection rules mapped to T1218.011 (SPL 35, KQL 23, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.

82 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1218 System Binary Proxy Execution](https://intel.threadlinqs.com/technique/T1218) — 170 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1218.011
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
