Malicious IFEO Debugger Hijack of vds.exe by FishMonger

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-08-14
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects registration of an Image File Execution Options Debugger value for vds.exe, a persistence and defense-evasion technique used by the FishMonger group deploying SprySOCKS. The activity abuses the IFEO mechanism so that a malicious binary is launched whenever the Virtual Disk Service is invoked. Detecting this key is important because it silently redirects execution of a legitimate system component to attacker-controlled code.

Related detections4 linkedT1546.012 — drag to rearrange
Suspicious Image File Execution Options Debugger Hijack by Miner Campaign
Suspicious Command Processor AutoRun Persistence via Registry Set
Windows Registry App Paths Default Property Change Using Suspicious Values
Windows Registry Persistence via Image File Execution Options GlobalFlag and SilentProcessExit
Malicious IFEO Debugger Hijack of vds.exe by FishMonger
Pivot detection · T1546.012 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.