Malicious Azure WireServer Access Impersonating WALinuxAgent (via process_creation)

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-07-29
Updated
2026-08-28

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a process contacting the Azure WireServer host address while presenting the WALinuxAgent identity, a technique used in the ChaosDB walkthrough to steal certificates and goal-state data. A non-agent process impersonating the Linux guest agent to reach WireServer is a strong sign of credential theft. Legitimate agent traffic originates from the agent binary itself, not ad-hoc curl commands.

Related detections9 linkedT1552.005 — drag to rearrange
Possible Jamf Pro SSRF Exploitation via eduFeatureSettingsTest imageUrl (via webserver)
Possible WebSphere Portal SSRF via Proxy Servlet targeting Cloud Metadata (CVE-2021-27748) (via webserver)
Possible SSRF to AWS Metadata via Workspace One UEM BlobHandler CVE-2021-22054
Possible SSRF via Gatsby _gatsby File Proxy Endpoint
Possible SSRF to Cloud Metadata via Nuxt _ipx Image Proxy
Suspicious Cloud Instance Metadata Access from Command Line (via process_creation)
Suspicious Access to Cloud and Database Credential Files via Process
Possible Super SSRF via Jira Server nativemobile batch CVE-2022-26135
Suspicious prt-scan Campaign Credential Harvesting via proc environ Scan (via process_creation)
Malicious Azure WireServer Access Impersonating WALinuxAgent (via process_creation)
Pivot detection · T1552.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.