Malicious PIPEDANCE Named Pipe Command and Control Channel via Pipe Created

PremiumReviewedSigma · High · v1
Product
windows
Category
pipe_created
Author
HuntRule
Published
2026-09-17
Updated
2026-09-17

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of the hardcoded PIPEDANCE named pipe used as an inter-process SMB command and control channel where the pipe name doubles as the RC4 key u0hxc1q44vhhbj5oo4ohjieo8uh7ufxe. PIPEDANCE uses this pipe to relay operator commands for shellcode injection and token hijacking so its presence indicates active backdoor communication.

Related detections9 linkedT1071.004 — drag to rearrange
Suspicious DNS Query for Tor Onion Domain
Possible DNS Tunneling via Excessively Long Query Name
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Suspicious Named Pipe Pipe2PortCtrl Created by Winnti Malware
Suspicious Script Download via Curl and PowerShell by Dohdoor
DoT (DNS Over TLS) Activation - Command (via process_creation)
DoT (DNS Over TLS) Activation - PowerShell (via powershell)
Possible C2 Beacon with Fixed Authorization URI Parameter via proxy
Suspicious FinCounter DNS Tunneling Query via dns_query
Malicious PIPEDANCE Named Pipe Command and Control Channel via Pipe Created
Pivot detection · T1071.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.