Rundll32 is a tool tracked by ThreatCluster, appearing in 11 threat clusters built from 14 intelligence report mentions.
Rundll32 is a tool tracked across 11 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity July 22, 2026.
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
The Belarus-aligned cyber group FrostyNeighbor has launched a targeted campaign against government organizations in Ukraine and Poland since March 2026. Utilizing spearphishing techniques, the group delivers malicious…
In May 2026, TrendAI™ Research reported on a cyber intrusion involving the ClearFake campaign, where threat actors utilized the EtherHiding technique to deliver payloads via smart contracts on the BNB Smart Chain…
A new variant of TrickBot has been identified using DNS tunneling instead of HTTP for command-and-control (C2) communication. This shift allows the malware to conceal its traffic within malformed DNS queries, making…
An exposed server functioning as a malware delivery lab was discovered following an MDR alert. The lab contained over 1,000 artifacts, showcasing how attackers are leveraging generative AI for rapid lure generation and…
The Lampion malware campaign, originating from Brazil, is actively targeting Portuguese organizations through phishing emails. Recent attacks impersonate private sector entities, such as automotive documentation…
On July 2, 2026, Opera introduced a new security feature called Paste Protect to prevent clipboard hijacking and code injection attacks, specifically targeting ClickFix-style attacks. These attacks trick users into…
Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…
Threat actors have leveraged phishing emails to initiate a multi-stage intrusion chain that deploys the AsyncRAT remote access trojan. This operation utilizes Cloudflare's free-tier infrastructure and legitimate Python…
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…
Rundll32 is a tool tracked by ThreatCluster, appearing in 11 threat clusters built from 14 intelligence report mentions.
The most recent intelligence report mentioning Rundll32 on ThreatCluster is dated July 22, 2026. Activity was first observed November 3, 2025, giving a tracked span from then to July 22, 2026.
Across ThreatCluster reporting, Rundll32 most frequently co-occurs with FrostyNeighbor, Lazarus Group, Pushcha, Stealth Falcon, Storm-0257, among 12 tracked related entities.
The most significant recent cluster is “Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks” (12 articles · Updated May 25, 2026). Rundll32 appears across 11 threat clusters in total, listed above with sources.
Rundll32 appears in 14 intelligence report mentions across 11 deduplicated threat clusters, aggregated from 17,000+ monitored sources.