Malicious Quantum Ransomware ttsel Payload Execution via Command Line

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-04
Updated
2026-10-04

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects execution of the ttsel.exe payload used during Quantum ransomware intrusions to stage tooling on compromised hosts. The named binary is a meaningful constant tied to this campaign chain that follows IcedID access. Its execution indicates hands-on-keyboard activity progressing toward ransomware deployment.

Related detections9 linkedT1055 — drag to rearrange
Malicious PowerShell Runtime Loaded Outside PowerShell Host
Suspicious App Domain Manager Injection via Environment Variables
Suspicious Svchost Execution from Non-Services Parent
Suspicious AutoIt Interpreter Launched by Script Host or Shell
Suspicious Salamander Named Pipe Creation
Suspicious DynamicWrapperX dynwrapx.dll Load Enabling Script Based Injection
Suspicious Image File Execution Options Debugger Hijack
Suspicious DllHost Spawned By MMC Without Arguments via PASTALOADER
Suspicious vbc.exe Spawned by Installer Process
Malicious Quantum Ransomware ttsel Payload Execution via Command Line
Pivot detection · T1055 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.