Malicious BADIIS Driver Dropped to System32 Drivers Directory (via file_event)

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects the BADIIS malicious kernel driver payloads being written into the System32 drivers directory under masquerading filenames. Observed in Elastic Security Labs analysis of the global SEO poisoning campaign where WUDFPfprot.sys, WppRecorderpo.sys, and WppRecorderrt.sys are dropped to establish a stealthy foothold.

Related detections9 linkedT1027 — drag to rearrange
Obfuscated Encoded PowerShell Payload Deployed via Service (via security)
Suspicious Service DLL Hijack of IKEEXT or PrintNotify
Suspicious PowerShell Invoke-Expression with Replace Obfuscation
Service Hiding via SC Sdset Security Descriptor Modification
Suspicious Base64 Decoded Payload Piped to Shell
Suspicious Shell Command Obfuscation via printf Escape Encoding on VMware ESXi (via process_creation)
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious TinyTurla ServiceDll Registration via svchost Group (via registry_set)
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Malicious BADIIS Driver Dropped to System32 Drivers Directory (via file_event)
Pivot detection · T1027 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.