Malicious LockBit Rundll32 Execution With gdll Export and -pass Argument

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-07-29
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule detects rundll32.exe invoking a DLL export named gdll together with a -pass argument, the loader pattern used by LockBit 3.0 payloads staged from a batch file on the user Desktop. Huntress observed operators abusing a TeamViewer session to drop and run this payload for ransomware deployment. Catching the export and password-flag combination flags encryptor execution before file encryption completes.

Related detections9 linkedT1486 — drag to rearrange
Possible Akira Ransomware Note or Encrypted Extension Creation
Malicious Storm-2603 Ransom Note File Creation
Possible Ransomware Note or Encrypted File Extension Creation
Malicious Rundll32 Loading an Export From a User Path (via process_creation)
Renamed Regsvr32 or Rundll32 Loading a DLL With a Non-Standard Extension (via process_creation)
BitLocker Feature Activation on Multiple Hosts - Native (via bitlocker)
FunkSec Ransomware Encryption Artifacts via funksec Extension and Markdown Ransom Note (via file_event)
Malicious Rundll32 DllRegisterServer Execution From a User-Writable Path (via process_creation)
IMEEX Framework DLL Execution via Rundll32 Loading imaadp (via process_creation)
Malicious LockBit Rundll32 Execution With gdll Export and -pass Argument
Pivot detection · T1486 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.