Threat actors across espionage, cybercrime, and ransomware operations have repeatedly abused the native Windows binary rundll32.exe to execute malicious DLLs, stage payloads, evade defenses, and maintain persistence. MITRE ATT&CK catalogs the technique as T1218.011 under System Binary Proxy Execution, citing use by groups and malware including APT28, APT29, Sandworm, QakBot, IcedID, Bumblebee, Bad Rabbit, NotPetya, Egregor, MegaCortex, and Ragnar Locker. The LOLBAS project likewise identifies rundll32.exe as a legitimate signed binary that can be repurposed to proxy malicious execution on Windows systems.
One documented abuse path uses setupapi.dll or iesetupapi.dll with the LaunchINFSection function to bypass application control and trigger arbitrary script or payload execution, a method also described in public research on INF/SCT fetch-and-execute tradecraft for evasion and persistence. Splunk previously published a detection for suspicious rundll32.exe command lines tied to this behavior before replacing it with a broader analytic for Windows application whitelisting bypass attempts, underscoring continued defender focus on rundll32.exe as a high-risk living-off-the-land execution vector.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Splunk removed the detection 'Detect Rundll32 Application Control Bypass - setupapi' from its Threat Research content library, stating it was deprecated and replaced by 'Windows Application Whitelisting Bypass Attempt via Rundll32.' The removal was recorded in version 5.18.0 and the page lists an updated date of 2026-05-13.
MITRE ATT&CK published the Enterprise technique entry for Signed Binary Proxy Execution: Rundll32 (T1218.011), documenting how adversaries abuse rundll32.exe to proxy execution of malicious DLLs, CPL files, and scripts. The entry also cataloged multiple threat actors and malware families observed using rundll32 and provided mitigation and detection guidance.
Palo Alto Networks Unit 42 published research on Sofacy Group's parallel attacks, documenting the group's use of rundll32-related execution tradecraft. This is a separate threat activity disclosure from the Sandworm and APT29 incidents already in the timeline.
Bohops published research on leveraging INF-SCT fetch-and-execute techniques for bypass, evasion, and persistence involving rundll32-related tradecraft. The publication itself is an explicit real-world disclosure event anchored by the reference date.
During the 2015 Ukraine Electric Power Attack, Sandworm Team used a backdoor capable of executing a supplied DLL via rundll32.exe. The ATT&CK reference cites this as an example of rundll32 abuse for malicious execution.
Trend Micro published a white paper detailing CPL malware, a form of malicious Control Panel item abuse commonly associated with rundll32 execution tradecraft. This is a separate technical disclosure event from the existing Bohops, ATT&CK, and Splunk entries.
During the SolarWinds compromise, APT29 used Rundll32.exe to execute payloads. The ATT&CK reference identifies this as part of the intrusion's execution tradecraft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceattack.mitre.org
Open sourceresearchcenter.paloaltonetworks.com
Open sourcebohops.com
Open sourcelolbas-project.github.io
Open sourceattack.mitre.org
Open sourcetrendmicro.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.