T1218.011 - Rundll32 is a mitre_attack tracked by ThreatCluster, appearing in 21 threat clusters built from 23 intelligence report mentions.
T1218.011 - Rundll32 is a mitre_attack tracked across 21 threat clusters and 23 intelligence report mentions on ThreatCluster. First observed December 6, 2025; most recent activity July 23, 2026.
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of critical vulnerabilities in Lantronix EDS5000-series devices and Ubiquiti's UniFi OS. The Lantronix vulnerability,…
The Vidar infostealer has evolved into a sophisticated multi-stage attack framework that utilizes fileless techniques to evade detection. Attackers embed malicious payloads within JPEG images and TXT documents,…
In June 2026, a new ransomware family named Spirals executed a double extortion attack against an IT services company in South Asia, completing the operation in under 24 hours. The attackers gained initial access by…
The ModHeader browser extension, used by approximately 1.6 million users across Chrome and Edge, was removed after researchers discovered a dormant data-collection capability embedded in its signed release. The…
From late April to mid-June 2026, ACR Stealer, a malware-as-a-service operation, has ramped up its activity targeting enterprise users by stealing browser credentials, session tokens, and sensitive documents. The attack…
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
A new variant of TrickBot has been identified using DNS tunneling instead of HTTP for command-and-control (C2) communication. This shift allows the malware to conceal its traffic within malformed DNS queries, making…
T1218.011 - Rundll32 is a mitre_attack tracked by ThreatCluster, appearing in 21 threat clusters built from 23 intelligence report mentions.
The most recent intelligence report mentioning T1218.011 - Rundll32 on ThreatCluster is dated July 23, 2026. Activity was first observed December 6, 2025, giving a tracked span from then to July 23, 2026.
Across ThreatCluster reporting, T1218.011 - Rundll32 most frequently co-occurs with Apt28, Apt32, Golden Chickens, Hafnium, Lazarus Group, among 12 tracked related entities.
The most significant recent cluster is “Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks” (12 articles · Updated May 25, 2026). T1218.011 - Rundll32 appears across 21 threat clusters in total, listed above with sources.
T1218.011 - Rundll32 appears in 23 intelligence report mentions across 21 deduplicated threat clusters, aggregated from 17,000+ monitored sources.