# T1218 System Binary Proxy Execution

> As of 2026-10-05, T1218 (System Binary Proxy Execution) appears in 170 tracked threats, first reported 2026-02-02 and most recently 2026-09-30, with linked actors including APT28, APT43, Forest Blizzard; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 170 (29 critical, 124 high, 14 medium, 1 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-30
- **Threat actors:** 61
- **Detection rules:** 120 (counts only; Blue tier and above)

## Key facts

- **ID:** T1218
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1218/

## Activity timeline

T1218 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 54 reports, and 170 of the 170 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1218 System Binary Proxy Execution is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 170 of 2623 tracked threats (6.5%) to it; by severity that is 29 critical, 124 high, 14 medium, 1 low.

Threats that use T1218 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (141 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (126 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (118 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (116 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (106 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

61 tracked threat actors appear in the threats that use T1218; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (7), [APT43](https://intel.threadlinqs.com/actor/APT43) (6), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (6), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (6), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (5).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1218.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)
- [M1050 Exploit Protection](https://attack.mitre.org/mitigations/M1050/)

## Data sources

Telemetry that can reveal T1218, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation
- Module — Module Load
- Network Traffic — Network Connection Creation
- Process — OS API Execution, Process Creation
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 7
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 6
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 6
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 6
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 5
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 4
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 3
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 3
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 3

## Tracked threats

The 30 most recent of 170 tracked threats that use T1218.

- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — high — 2026-09-30
- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…](https://intel.threadlinqs.com/threat/TL-2026-2730) — high — 2026-09-28
- [OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)](https://intel.threadlinqs.com/threat/TL-2026-2628) — high — 2026-09-23
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2452) — high — 2026-09-11
- [LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique](https://intel.threadlinqs.com/threat/TL-2026-2441) — medium — 2026-09-11
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE…](https://intel.threadlinqs.com/threat/TL-2026-2369) — high — 2026-09-07
- [Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2](https://intel.threadlinqs.com/threat/TL-2026-2368) — high — 2026-09-07
- [TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India](https://intel.threadlinqs.com/threat/TL-2026-2202) — high — 2026-08-29
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…](https://intel.threadlinqs.com/threat/TL-2026-2163) — high — 2026-08-27
- [SmartApeSG ClickFix Campaign Delivering Two-Stage RAT Infection via Fake CAPTCHA Social Engineering on…](https://intel.threadlinqs.com/threat/TL-2026-2101) — high — 2026-08-21
- [WordlistLoader Delivering Amatera (ACR Stealer) via ClearFake FakeCaptcha Campaigns](https://intel.threadlinqs.com/threat/TL-2026-2367) — high — 2026-08-18
- [Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)](https://intel.threadlinqs.com/threat/TL-2026-2040) — high — 2026-08-17
- [Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…](https://intel.threadlinqs.com/threat/TL-2026-1983) — medium — 2026-08-11
- [CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for…](https://intel.threadlinqs.com/threat/TL-2026-1932) — 2026-08-07
- [Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1901) — critical — 2026-08-05
- [Google Blogger Automated Malware False Positive Locks Hundreds of Blogs — Platform-Wide Enforcement Error…](https://intel.threadlinqs.com/threat/TL-2026-1890) — low — 2026-08-05
- [Ransomware Attack on QNET Disrupted by Microsoft Defender Automatic Device Isolation in 128 Seconds…](https://intel.threadlinqs.com/threat/TL-2026-1869) — high — 2026-08-04
- [Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)](https://intel.threadlinqs.com/threat/TL-2026-1846) — high — 2026-08-03
- [Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquatting](https://intel.threadlinqs.com/threat/TL-2026-1845) — high — 2026-08-03
- [State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…](https://intel.threadlinqs.com/threat/TL-2026-1780) — critical — 2026-07-31
- [Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…](https://intel.threadlinqs.com/threat/TL-2026-1766) — critical — 2026-07-30
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC](https://intel.threadlinqs.com/threat/TL-2026-1730) — 2026-07-27
- [MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal…](https://intel.threadlinqs.com/threat/TL-2026-1723) — high — 2026-07-27
- [AWS SSM Agent Abused as a Living-off-the-Land Remote Access Trojan via Hybrid-Activation Hijacking and…](https://intel.threadlinqs.com/threat/TL-2026-1709) — medium — 2026-07-26
- [msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaS](https://intel.threadlinqs.com/threat/TL-2026-1694) — high — 2026-07-25
- [TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2](https://intel.threadlinqs.com/threat/TL-2026-1684) — high — 2026-07-23

## Related CVEs

CVEs referenced by the tracked threats that use T1218, most frequent first.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21514](https://intel.threadlinqs.com/cve/CVE-2026-21514)
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519)
- [CVE-2026-21522](https://intel.threadlinqs.com/cve/CVE-2026-21522)
- [CVE-2026-21525](https://intel.threadlinqs.com/cve/CVE-2026-21525)
- [CVE-2026-21532](https://intel.threadlinqs.com/cve/CVE-2026-21532)
- [CVE-2026-21533](https://intel.threadlinqs.com/cve/CVE-2026-21533)
- [CVE-2026-23655](https://intel.threadlinqs.com/cve/CVE-2026-23655)
- [CVE-2026-24300](https://intel.threadlinqs.com/cve/CVE-2026-24300)
- [CVE-2026-24302](https://intel.threadlinqs.com/cve/CVE-2026-24302)
- [CVE-2014-4114](https://intel.threadlinqs.com/cve/CVE-2014-4114)
- [CVE-2017-11882](https://intel.threadlinqs.com/cve/CVE-2017-11882)
- [CVE-2017-8570](https://intel.threadlinqs.com/cve/CVE-2017-8570)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2023-46604](https://intel.threadlinqs.com/cve/CVE-2023-46604)
- [CVE-2023-49105](https://intel.threadlinqs.com/cve/CVE-2023-49105)

## Detection coverage

Threadlinqs maintains 120 detection rules mapped to T1218 (SPL 47, KQL 41, Sigma 32). Rule content is available to Blue tier accounts and above; this page shows counts only.

120 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1218.001 Compiled HTML File — 5 tracked threats
- T1218.002 Control Panel — 2 tracked threats
- T1218.003 CMSTP — 4 tracked threats
- T1218.004 InstallUtil — 1 tracked threat
- [T1218.005 Mshta](https://intel.threadlinqs.com/technique/T1218.005) — 37 tracked threats
- [T1218.007 Msiexec](https://intel.threadlinqs.com/technique/T1218.007) — 37 tracked threats
- T1218.008 Odbcconf — 0 tracked threats
- T1218.009 Regsvcs/Regasm — 4 tracked threats
- [T1218.010 Regsvr32](https://intel.threadlinqs.com/technique/T1218.010) — 14 tracked threats
- [T1218.011 Rundll32](https://intel.threadlinqs.com/technique/T1218.011) — 30 tracked threats
- T1218.012 Verclsid — 0 tracked threats
- T1218.013 Mavinject — 0 tracked threats
- T1218.014 MMC — 1 tracked threat
- T1218.015 Electron Applications — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1218
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
