Cleo File Transfer Software Spawning Command Interpreter

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-11
Updated
2026-08-28

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a Cleo managed file transfer process spawning a command interpreter such as cmd, PowerShell or Bash, the post-exploitation behavior of CVE-2024-55956 autorun abuse leading to Cobalt Strike by CL0P. A Cleo product launching a shell indicates exploitation of the Cleo Harmony VLTrader or LexiCom software.

Related detections9 linkedT1190 — drag to rearrange
Possible Bitbucket Pre-Auth RCE via git archive exec Null-Byte Injection (CVE-2022-36804) (via webserver)
Malicious ActiveMQ Exploitation Java Spawning PowerShell Downloader (via process_creation)
Suspicious Cleo Autorun Health Check File Drop (via file_event)
Obfuscated IIS Worker Spawning Encoded PowerShell after SharePoint ToolShell (via process_creation)
Malicious WSUS Service Spawning Command Shell via Remote Code Execution
Malicious PostgreSQL COPY FROM PROGRAM Command Execution via Managed Cloud Database (via process_creation)
Malicious PowerShell Spawned by IIS Worker Process via OWASSRF Exchange Exploitation (via process_creation)
Suspicious PAN-OS Shell Execution Setting panusername via Command Injection (via process_creation)
Suspicious Child Process Spawned From Java Following Web Exploitation
Cleo File Transfer Software Spawning Command Interpreter
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.