Malicious Child Process Spawned From n8n Node Process

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Initial Access → Discovery
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects a Node.js process running n8n spawning shell, discovery or downloader child processes such as sh, whoami, wget or curl, the exploitation behavior of the Zerobot botnet abusing the CVE-2025-68613 expression sandbox escape. The n8n workflow engine should not launch system commands, so these child spawns indicate remote code execution with n8n process privileges. This pattern reflects active post-exploitation on the host.

Related detections9 linkedT1059.004 — drag to rearrange
Suspicious AI Agent Compromise via Web Worker Spawning Shell or Network Tool
Malicious wp2shell WordPress RCE via Web Server Spawning Shell Recon
Malicious Node.js Process Spawning Unix Shell or Network Client
Suspicious Shell Spawned by ActiveMQ Java Process
Possible Bitbucket Pre-Auth RCE via git archive exec Null-Byte Injection (CVE-2022-36804) (via webserver)
Malicious PostgreSQL COPY FROM PROGRAM Command Execution via Managed Cloud Database (via process_creation)
Suspicious PAN-OS Shell Execution Setting panusername via Command Injection (via process_creation)
Malicious OMI Server Spawning Shell as Root via OMIGOD SCX Provider (via process_creation)
Possible F5 iControl REST Remote Code Execution via Util Bash Endpoint
Malicious Child Process Spawned From n8n Node Process
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.