Malicious GitVenom Python Fernet Decrypt-and-Execute Loader via process_creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-08
Updated
2026-10-08

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a python.exe process whose command line combines the exec builtin with the cryptography Fernet primitive to decrypt and run an embedded payload in memory. This behavior was used by the GitVenom campaign which hid malicious loaders inside fake GitHub projects. Attackers use runtime decryption to hide stealer and RAT code from static inspection which makes early loader detection valuable.

Related detections9 linkedT1059.006 — drag to rearrange
Suspicious Python Executing Script from var root Library Caches on macOS (via process_creation)
Suspicious Python Script Persistence in User Startup Folder
Suspicious cmd.exe Spawned by python.exe (via process_creation)
Certutil Decoding Encoded Payload to Executable
Possible Langflow Unauthenticated Code Execution via validate code Endpoint (via webserver)
Suspicious Certutil Decode of Payload to Executable
Suspicious Node.js Spawning Python or Tar Interpreter
Suspicious File Concatenation via copy Binary Mode
Suspicious CAB Extraction via extrac32 LOLBin
Malicious GitVenom Python Fernet Decrypt-and-Execute Loader via process_creation
Pivot detection · T1059.006 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.