Malicious Masquerading TiWorker Spawning PowerShell Downloader via process_creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-17
Updated
2026-09-17

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a masquerading TiWorker.exe process spawning PowerShell to fetch a remotely hosted payload disguised as a PNG image, matching the GHOSTENGINE crypto mining infection chain. The legitimate TiWorker.exe is a Windows Modules Installer worker and does not normally launch PowerShell download activity. This behavior indicates process masquerading for initial payload retrieval.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious PowerShell Masquerading as wt.exe in ProgramData via Axios npm Compromise (via process_creation)
Malicious Axios NPM RAT Renamed PowerShell Execution via wt.exe
Windows: Process executions matching Greenbug espionage tool indicators
Suspicious PowerShell BITS Transfer of DLL Payload via process_creation
Suspicious Print Filter Pipeline Host Running Outside System32 via Process Creation
Suspicious Script Host Spawning PowerShell via Process Creation
Suspicious PIKABOT PowerShell Download to Public Directory via Process Creation
Malicious SQL Server Command Execution Spawning Download Utilities via Process Creation
Malicious TELEPUZ DLL Persistence via Masqueraded Loader in User Path
Malicious Masquerading TiWorker Spawning PowerShell Downloader via process_creation
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.