LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1218.010: Regsvr32

Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. The Regsvr32.exe binary may also be signed by Microsoft. [1]

Malicious usage of Regsvr32.exe may avoid triggering security tools that may not monitor execution of, and modules loaded by, the regsvr32.exe process because of allowlists or false positives from Windows using regsvr32.exe for normal operations. Regsvr32.exe can also be used to specifically bypass application control using functionality to load COM scriptlets to execute DLLs under user permissions. Since Regsvr32.exe is network and proxy aware, the scripts can be loaded by passing a uniform resource locator (URL) to file on an external Web server as an argument during invocation. This method makes no changes to the Registry as the COM object is not actually registered, only executed. [2] This variation of the technique is often referred to as a "Squiblydoo" and has been used in campaigns targeting governments. [3] [4]

Regsvr32.exe can also be leveraged to register a COM Object used to establish persistence via Component Object Model Hijacking. [3]

EnterpriseT1218.010Sub-techniqueObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Regsvr32 matters because it is a legitimate Microsoft-signed Windows utility that can be abused to run malicious code while appearing like normal system activity. For leaders, the risk is not the tool itself; it is whether Windows monitoring, application control, and incident response processes can distinguish legitimate registration activity from proxy execution, remote scriptlet loading, or related persistence activity.

Executive priority

Prioritize this technique where Windows endpoints support critical business operations, regulated workflows, or privileged administration. It is a practical test of whether the organization’s controls can handle “living off the land” behavior: trusted binaries, user-permission execution, network-aware invocation, and activity that may not modify the Registry. Ask whether SOC playbooks, endpoint telemetry, and application-control evidence can prove coverage for suspicious Regsvr32 use without creating excessive false positives from normal Windows operations.

Technical view

Validate detection around regsvr32.exe process execution, command-line arguments, parent/child process context, network connections, and modules or COM/scriptlet-related activity. ATT&CK provides no official detection text for this object, but the relationship to DET0282 indicates a specific detection strategy exists for System Binary Proxy Execution: Regsvr32. Analysts should also account for the relationship to System Binary Proxy Execution (T1218) and possible persistence linkage through Component Object Model Hijacking referenced in the description. Focus triage on unusual Regsvr32 execution paths, external URL references, unexpected parent processes, execution under user permissions, and cases where allowlists may suppress review.

Likely telemetry

  • Windows process creation events for regsvr32.exe, including full command line
  • Parent and child process relationships around regsvr32.exe
  • Network connection telemetry from regsvr32.exe, including proxy-aware outbound activity
  • Loaded module or DLL telemetry associated with regsvr32.exe
  • Application control, allowlist, or endpoint protection decision logs

Detection direction

  • Validate that regsvr32.exe is not globally trusted without behavioral inspection.
  • Tune for suspicious command-line patterns and URL-based loading while preserving known-good administrative and software installation activity.
  • Correlate Regsvr32 execution with network telemetry because the technique description notes that it can load scripts from external web servers.
  • Review endpoint tooling blind spots around Microsoft-signed binaries, module loads, and allowlist exceptions.
  • Use relationship context carefully: multiple ATT&CK campaigns, groups, and software entries are linked to this technique, but local detection should be behavior-based rather than attribution-led.

Mitigation priorities

  • Apply application-control policy review so legitimate Regsvr32 use is understood and suspicious abuse is constrained where operationally feasible.
  • Use exploit protection capabilities identified by M1050 as part of a broader hardening approach, while recognizing they do not replace behavior monitoring.
  • Reduce unnecessary user ability to execute unapproved scripts, DLL-related workflows, or remote content through trusted binaries.
  • Ensure proxy, endpoint, and SOC controls preserve enough command-line, network, and process context to support investigation.
  • Document legitimate business uses of Regsvr32 so exceptions are auditable and false positives can be tuned without creating broad bypasses.
Additional notes and limits

This is a Windows sub-technique of System Binary Proxy Execution under the stealth tactic. MITRE notes abuse of Regsvr32 for proxy execution, possible application-control bypass using COM scriptlets, network/URL-based loading, and potential use in COM Object persistence scenarios. The relationship set includes multiple campaigns, groups, and software families using the technique, plus a detection strategy relationship and Exploit Protection mitigation relationship.

The supplied ATT&CK object does not include official detection guidance. This take does not assert current exploitation, customer exposure, or guaranteed detection. Local baselines are required because Regsvr32 has legitimate Windows and administrative uses, and overly broad blocking or alerting may affect operations.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Regsvr32

Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. The Regsvr32.exe binary may also be signed by Microsoft. [1]

Malicious usage of Regsvr32.exe may avoid triggering security tools that may not monitor execution of, and modules loaded by, the regsvr32.exe process because of allowlists or false positives from Windows using regsvr32.exe for normal operations. Regsvr32.exe can also be used to specifically bypass application control using functionality to load COM scriptlets to execute DLLs under user permissions. Since Regsvr32.exe is network and proxy aware, the scripts can be loaded by passing a uniform resource locator (URL) to file on an external Web server as an argument during invocation. This method makes no changes to the Registry as the COM object is not actually registered, only executed. [2] This variation of the technique is often referred to as a "Squiblydoo" and has been used in campaigns targeting governments. [3] [4]

Regsvr32.exe can also be leveraged to register a COM Object used to establish persistence via Component Object Model Hijacking. [3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1218System Binary Proxy ExecutionThis object subtechnique of System Binary Proxy Execution.
EnterpriseT1117Regsvr32Regsvr32 revoked by this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0127: TA551

TA551 is a financially-motivated threat group that has been active since at least 2018. [1] The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns. [2]

GroupEnterprise

G0009: Deep Panda

Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. [1] The intrusion into healthcare company Anthem has been attributed to Deep Panda. [2] This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. [3] Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. [4] Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same. [5]

GroupEnterprise

G0080: Cobalt Group

Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims.[1][2][3][4][5][6][7] Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.[8]

GroupEnterprise

G1053: Storm-0501

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.[1][2][3][4]

GroupEnterprise

G0108: Blue Mockingbird

Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.[1]

GroupEnterprise

G0065: Leviathan

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.[1] Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.[1][2][3][4]

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0100: Inception

Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.[1][2][3]

GroupEnterprise

G0090: WIRTE

WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. WIRTE has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.[1][2][3][4]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

GroupEnterprise

G0073: APT19

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. [1] Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same. [2] [3] [4]

MalwareEnterprise

S0650: QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

Windows
MalwareEnterprise

S0367: Emotet

Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID. Emotet first emerged in June 2014, initially targeting the financial sector, and has expanded to multiple verticals over time.[1]

Windows
MalwareEnterprise

S0229: Orz

Orz is a custom JavaScript backdoor used by Leviathan. It was observed being used in 2014 as well as in August 2017 when it was dropped by Microsoft Publisher files. [1] [2]

Windows
ToolEnterprise

S0250: Koadic

Koadic is a Windows post-exploitation framework and penetration testing tool that is publicly available on GitHub. Koadic has several options for staging payloads and creating implants, and performs most of its operations using Windows Script Host.[1][2][3]

Windows
MalwareEnterprise

S0476: Valak

Valak is a multi-stage modular malware that can function as a standalone information stealer or downloader, first observed in 2019 targeting enterprises in the US and Germany.[1][2]

Windows
ToolEnterprise

S1155: Covenant

Covenant is a multi-platform command and control framework written in .NET. While designed for penetration testing and security research, the tool has also been used by threat actors such as HAFNIUM during operations. Covenant functions through a central listener managing multiple deployed "Grunts" that communicate back to the controller.[1][2]

LinuxmacOSWindows
MalwareEnterprise

S0373: Astaroth

Astaroth is a Trojan and information stealer known to affect companies in Europe, Brazil, and throughout Latin America. It has been known publicly since at least late 2017. [1][2][3]

Windows
MalwareEnterprise

S0384: Dridex

Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex).[1][2][3]

Windows
MalwareEnterprise

S1130: Raspberry Robin

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.[1][2][3] The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."[4] The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.[5]

Windows
CampaignEnterprise

C0022: Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

CampaignEnterprise

C0015: C0015

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.[1]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
223484cd647fe6d9...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.0Current bundle223484cd647f…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Microsoft Regsvr32

    Microsoft. (2015, August 14). How to use the Regsvr32 tool and troubleshoot Regsvr32 error messages. Retrieved June 22, 2016.

    Open source URL
  2. [2]
    LOLBAS Regsvr32

    LOLBAS. (n.d.). Regsvr32.exe. Retrieved July 31, 2019.

    Open source URL
  3. [3]
    Carbon Black Squiblydoo Apr 2016

    Nolen, R. et al.. (2016, April 28). Threat Advisory: “Squiblydoo” Continues Trend of Attackers Using Native OS Tools to “Live off the Land”. Retrieved April 9, 2018.

    Open source URL
  4. [4]
    FireEye Regsvr32 Targeting Mongolian Gov

    Anubhav, A., Kizhakkinan, D. (2017, February 22). Spear Phishing Techniques Used in Attacks Targeting the Mongolian Government. Retrieved February 24, 2017.

    Open source URL
  5. [5]
    Malwarebytes Saint Bot April 2021

    Hasherezade. (2021, April 6). A deep dive into Saint Bot, a new downloader. Retrieved June 9, 2022.

    Open source URL
  6. [6]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  7. [7]
    Red Canary Qbot

    Rainey, K. (n.d.). Qbot. Retrieved September 27, 2021.

    Open source URL
  8. [8]
    Cyberint Qakbot May 2021

    Cyberint. (2021, May 25). Qakbot Banking Trojan. Retrieved September 27, 2021.

    Open source URL
  9. [9]
    ATT QakBot April 2021

    Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.

    Open source URL
  10. [10]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  11. [11]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  12. [12]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  13. [13]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  14. [14]
    emotet_trendmicro_mar2023

    Kenefick, I. (2023, March 13). Emotet Returns, Now Adopts Binary Padding for Evasion. Retrieved June 19, 2024.

    Open source URL
  15. [15]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  16. [16]
    Github Koadic

    Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024.

    Open source URL
  17. [17]
    Cybereason Valak May 2020

    Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.

    Open source URL
  18. [18]
    ZScaler Squirrelwaffle Sep 2021

    Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.

    Open source URL
  19. [19]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  20. [20]
    Github Covenant

    cobbr. (2021, April 21). Covenant. Retrieved September 4, 2024.

    Open source URL
  21. [21]
    Cybereason Astaroth Feb 2019

    Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.

    Open source URL
  22. [22]
    Red Canary Dridex Threat Report 2021

    Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

    Open source URL
  23. [23]
    RedCanary RaspberryRobin 2022

    Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.

    Open source URL
  24. [24]
    ThreatGeek Derusbi Converge

    Fidelis Threat Research Team. (2016, May 2). Turbo Twist: Two 64-bit Derusbi Strains Converge. Retrieved August 16, 2018.

    Open source URL
  25. [25]
    RSA Shell Crew

    RSA Incident Response. (2014, January). RSA Incident Response Emerging Threat Profile: Shell Crew. Retrieved January 14, 2016.

    Open source URL
  26. [26]
    Unit42 DarkHydrus Jan 2019

    Lee, B., Falcone, R. (2019, January 18). DarkHydrus delivers new Trojan that can use Google Drive for C2 communications. Retrieved April 17, 2019.

    Open source URL
  27. [27]
    Talos Cobalt Group July 2018

    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

    Open source URL
  28. [28]
    Morphisec Cobalt Gang Oct 2018

    Gorelik, M. (2018, October 08). Cobalt Group 2.0. Retrieved November 5, 2018.

    Open source URL
  29. [29]
    TrendMicro Cobalt Group Nov 2017

    Giagone, R., Bermejo, L., and Yarochkin, F. (2017, November 20). Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks. Retrieved March 7, 2019.

    Open source URL
  30. [30]
    Trend Micro Mustang Panda Earth Preta Toneshell February 2025

    Nathaniel Morales, Nick Dai. (2025, February 18). Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection. Retrieved September 10, 2025.

    Open source URL
  31. [31]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  32. [32]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  33. [33]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  34. [34]
    RedCanary Mockingbird May 2020

    Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

    Open source URL
  35. [35]
    Secure Host Baseline EMET

    National Security Agency. (2016, May 4). Secure Host Baseline EMET. Retrieved June 22, 2016.

    Open source URL
  36. [36]
    Beechey 2010

    Beechey, J. (2010, December). Application Whitelisting: Panacea or Propaganda?. Retrieved November 18, 2014.

  37. [37]
    Microsoft Windows Defender Application Control

    Gorzelany, A., Hall, J., Poggemeyer, L.. (2019, January 7). Windows Defender Application Control. Retrieved July 16, 2019.

    Open source URL
  38. [38]
    Windows Commands JPCERT

    Tomonaga, S. (2016, January 26). Windows Commands Abused by Attackers. Retrieved February 2, 2016.

    Open source URL
  39. [39]
    NSA MS AppLocker

    NSA Information Assurance Directorate. (2014, August). Application Whitelisting Using Microsoft AppLocker. Retrieved March 31, 2016.

    Open source URL
  40. [40]
    Corio 2008

    Corio, C., & Sayana, D. P. (2008, June). Application Lockdown with Software Restriction Policies. Retrieved September 12, 2024.

    Open source URL
  41. [41]
    TechNet Applocker vs SRP

    Microsoft. (2012, June 27). Using Software Restriction Policies and AppLocker Policies. Retrieved April 7, 2016.

    Open source URL
  42. [42]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  43. [43]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  44. [44]
    DFIR Conti Bazar Nov 2021

    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

    Open source URL
  45. [45]
    Gen Digital Kimsuky HTTPTroy October 2025

    Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026.

    Open source URL
  46. [46]
    KISA Operation Muzabi

    KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

    Open source URL
  47. [47]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  48. [48]
    Lab52 WIRTE Apr 2019

    S2 Grupo. (2019, April 2). WIRTE Group attacking the Middle East. Retrieved May 24, 2019.

    Open source URL
  49. [49]
    Security Intelligence More Eggs Aug 2019

    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

    Open source URL
  50. [50]
    ESET OceanLotus Mar 2019

    Dumont, R. (2019, March 20). Fake or Fake: Keeping up with OceanLotus decoys. Retrieved April 1, 2019.

    Open source URL
  51. [51]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  52. [52]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  53. [53]
    ESET EvilNum July 2020

    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

    Open source URL
  54. [54]
    Fidelis INOCNATION

    Fidelis Cybersecurity. (2015, December 16). Fidelis Threat Advisory #1020: Dissecting the Malware Involved in the INOCNATION Campaign. Retrieved November 17, 2024.

    Open source URL
  55. [55]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  56. [56]
    Unit42 Xbash Sept 2018

    Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.

    Open source URL
  57. [57]
    FireEye APT19

    Ahl, I. (2017, June 06). Privileges and Credentials: Phished at the Request of Counsel. Retrieved May 17, 2018.

    Open source URL
  58. [58]
    Carbon Black Squiblydoo Apr 2016

    Nolen, R. et al.. (2016, April 28). Threat Advisory: “Squiblydoo” Continues Trend of Attackers Using Native OS Tools to “Live off the Land”. Retrieved April 9, 2018.

    Open source URL
  59. [59]
    Carbon Black Squiblydoo Apr 2016

    Nolen, R. et al.. (2016, April 28). Threat Advisory: “Squiblydoo” Continues Trend of Attackers Using Native OS Tools to “Live off the Land”. Retrieved April 9, 2018.

    Open source URL
  60. [60]
    FireEye Regsvr32 Targeting Mongolian Gov

    Anubhav, A., Kizhakkinan, D. (2017, February 22). Spear Phishing Techniques Used in Attacks Targeting the Mongolian Government. Retrieved February 24, 2017.

    Open source URL
  61. [61]
    FireEye Regsvr32 Targeting Mongolian Gov

    Anubhav, A., Kizhakkinan, D. (2017, February 22). Spear Phishing Techniques Used in Attacks Targeting the Mongolian Government. Retrieved February 24, 2017.

    Open source URL
  62. [62]
    LOLBAS Regsvr32

    LOLBAS. (n.d.). Regsvr32.exe. Retrieved July 31, 2019.

    Open source URL
  63. [63]
    LOLBAS Regsvr32

    LOLBAS. (n.d.). Regsvr32.exe. Retrieved July 31, 2019.

    Open source URL
  64. [64]
    Microsoft Regsvr32

    Microsoft. (2015, August 14). How to use the Regsvr32 tool and troubleshoot Regsvr32 error messages. Retrieved June 22, 2016.

    Open source URL
  65. [65]
    Microsoft Regsvr32

    Microsoft. (2015, August 14). How to use the Regsvr32 tool and troubleshoot Regsvr32 error messages. Retrieved June 22, 2016.

    Open source URL
  66. [66]
    mitre-attackT1218.010
    Open source URL
  67. [67]
    mitre-attackT1218.010
    Open source URL
  68. [68]
    mitre-attackT1218.010
    Open source URL
  69. [69]
    Malwarebytes Saint Bot April 2021

    Hasherezade. (2021, April 6). A deep dive into Saint Bot, a new downloader. Retrieved June 9, 2022.

    Open source URL
  70. [70]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  71. [71]
    ATT QakBot April 2021

    Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.

    Open source URL
  72. [72]
    Cyberint Qakbot May 2021

    Cyberint. (2021, May 25). Qakbot Banking Trojan. Retrieved September 27, 2021.

    Open source URL
  73. [73]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  74. [74]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  75. [75]
    Red Canary Qbot

    Rainey, K. (n.d.). Qbot. Retrieved September 27, 2021.

    Open source URL
  76. [76]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  77. [77]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  78. [78]
    emotet_trendmicro_mar2023

    Kenefick, I. (2023, March 13). Emotet Returns, Now Adopts Binary Padding for Evasion. Retrieved June 19, 2024.

    Open source URL
  79. [79]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  80. [80]
    Github Koadic

    Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024.

    Open source URL
  81. [81]
    Cybereason Valak May 2020

    Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.

    Open source URL
  82. [82]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  83. [83]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  84. [84]
    ZScaler Squirrelwaffle Sep 2021

    Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.

    Open source URL
  85. [85]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  86. [86]
    Github Covenant

    cobbr. (2021, April 21). Covenant. Retrieved September 4, 2024.

    Open source URL
  87. [87]
    Cybereason Astaroth Feb 2019

    Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.

    Open source URL
  88. [88]
    Red Canary Dridex Threat Report 2021

    Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

    Open source URL
  89. [89]
    RedCanary RaspberryRobin 2022

    Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.

    Open source URL
  90. [90]
    ThreatGeek Derusbi Converge

    Fidelis Threat Research Team. (2016, May 2). Turbo Twist: Two 64-bit Derusbi Strains Converge. Retrieved August 16, 2018.

    Open source URL
  91. [91]
    RSA Shell Crew

    RSA Incident Response. (2014, January). RSA Incident Response Emerging Threat Profile: Shell Crew. Retrieved January 14, 2016.

    Open source URL
  92. [92]
    Unit42 DarkHydrus Jan 2019

    Lee, B., Falcone, R. (2019, January 18). DarkHydrus delivers new Trojan that can use Google Drive for C2 communications. Retrieved April 17, 2019.

    Open source URL
  93. [93]
    Morphisec Cobalt Gang Oct 2018

    Gorelik, M. (2018, October 08). Cobalt Group 2.0. Retrieved November 5, 2018.

    Open source URL
  94. [94]
    Talos Cobalt Group July 2018

    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

    Open source URL
  95. [95]
    TrendMicro Cobalt Group Nov 2017

    Giagone, R., Bermejo, L., and Yarochkin, F. (2017, November 20). Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks. Retrieved March 7, 2019.

    Open source URL
  96. [96]
    Trend Micro Mustang Panda Earth Preta Toneshell February 2025

    Nathaniel Morales, Nick Dai. (2025, February 18). Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection. Retrieved September 10, 2025.

    Open source URL
  97. [97]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  98. [98]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  99. [99]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  100. [100]
    RedCanary Mockingbird May 2020

    Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

    Open source URL
  101. [101]
    Beechey 2010

    Beechey, J. (2010, December). Application Whitelisting: Panacea or Propaganda?. Retrieved November 18, 2014.

  102. [102]
    Corio 2008

    Corio, C., & Sayana, D. P. (2008, June). Application Lockdown with Software Restriction Policies. Retrieved September 12, 2024.

    Open source URL
  103. [103]
    Microsoft Windows Defender Application Control

    Gorzelany, A., Hall, J., Poggemeyer, L.. (2019, January 7). Windows Defender Application Control. Retrieved July 16, 2019.

    Open source URL
  104. [104]
    NSA MS AppLocker

    NSA Information Assurance Directorate. (2014, August). Application Whitelisting Using Microsoft AppLocker. Retrieved March 31, 2016.

    Open source URL
  105. [105]
    Secure Host Baseline EMET

    National Security Agency. (2016, May 4). Secure Host Baseline EMET. Retrieved June 22, 2016.

    Open source URL
  106. [106]
    TechNet Applocker vs SRP

    Microsoft. (2012, June 27). Using Software Restriction Policies and AppLocker Policies. Retrieved April 7, 2016.

    Open source URL
  107. [107]
    Windows Commands JPCERT

    Tomonaga, S. (2016, January 26). Windows Commands Abused by Attackers. Retrieved February 2, 2016.

    Open source URL
  108. [108]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  109. [109]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  110. [110]
    DFIR Conti Bazar Nov 2021

    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

    Open source URL
  111. [111]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  112. [112]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  113. [113]
    Gen Digital Kimsuky HTTPTroy October 2025

    Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026.

    Open source URL
  114. [114]
    KISA Operation Muzabi

    KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

    Open source URL
  115. [115]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  116. [116]
    Lab52 WIRTE Apr 2019

    S2 Grupo. (2019, April 2). WIRTE Group attacking the Middle East. Retrieved May 24, 2019.

    Open source URL
  117. [117]
    Security Intelligence More Eggs Aug 2019

    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.