Malicious Equation Editor Child Process Indicating Exploit

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-09-18
Updated
2026-09-18

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the Microsoft Equation Editor eqnedt32.exe spawning any child process, which indicates successful exploitation of an Office document delivering the FORMBOOK stealer. The legitimate equation editor never launches other executables, so any child process is a high-confidence exploit signal.

Related detections9 linkedT1203 — drag to rearrange
Malicious Microsoft Word Spawning Anomalous Child Process via CVE-2023-36884 (via process_creation)
Malicious Equation Editor Child Process Execution via process_creation
Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Malicious Foomatic-Rip Filter Spawning Shell via CUPS Exploitation
Suspicious Child Process Spawned by WinRAR via Process Creation
Suspicious mstsc Launch of RDP File From User Download or Temp Path (via process_creation)
Malicious Equation Editor Child Process Indicating Exploit
Pivot detection · T1203 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.