Netskope Threat Labs

RunDll

ATP Sandbox Adv. Heuristics

This generic detection identifies abuse of the Windows rundll32 utility to execute malicious code from dynamic link libraries, a technique that blends into normal system activity.

First seen
March 2022
Last seen
October 2026
Rundll
Alert Name
Win32.Trojan.Rundll
Win32.Trojan.RunDll
Win64.Trojan.RunDll