T1218.011 - Rundll32 - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
23
occurrences
First Seen
December 6, 2025
Last Seen
July 23, 2026

T1218.011 - Rundll32 is a mitre_attack tracked by ThreatCluster, appearing in 21 threat clusters built from 23 intelligence report mentions.

T1218.011 - Rundll32 is a mitre_attack tracked across 21 threat clusters and 23 intelligence report mentions on ThreatCluster. First observed December 6, 2025; most recent activity July 23, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • TAG — Recordedfuture · July 23, 2026
  • TrickBot Ditches HTTP for DNS Tunneling in Latest Variant — Infosecurity-Magazine · July 22, 2026
  • Lampion's Portugal-focused phishing campaign delivers multistage malware — Acronis · July 21, 2026
  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • New Spirals Ransomware Deployed Across South Asian IT Firm in Under 24 Hours — www.security.com · July 19, 2026
  • ACR Stealer Uses ClickFix, WebDAV, and Steganography to Steal Browser Credentials and Tokens — Gbhackers · July 17, 2026
  • Seraph Secure — www.seraphsecure.com · July 2, 2026

Frequently asked questions

What is T1218.011 - Rundll32?

T1218.011 - Rundll32 is a mitre_attack tracked by ThreatCluster, appearing in 21 threat clusters built from 23 intelligence report mentions.

Is T1218.011 - Rundll32 still active?

The most recent intelligence report mentioning T1218.011 - Rundll32 on ThreatCluster is dated July 23, 2026. Activity was first observed December 6, 2025, giving a tracked span from then to July 23, 2026.

What is T1218.011 - Rundll32 associated with?

Across ThreatCluster reporting, T1218.011 - Rundll32 most frequently co-occurs with Apt28, Apt32, Golden Chickens, Hafnium, Lazarus Group, among 12 tracked related entities.

What are the latest developments involving T1218.011 - Rundll32?

The most significant recent cluster is “Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks” (12 articles · Updated May 25, 2026). T1218.011 - Rundll32 appears across 21 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1218.011 - Rundll32?

T1218.011 - Rundll32 appears in 23 intelligence report mentions across 21 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown