Malicious Ransomware Payload Execution via HWP Word Processor Spawning Executable from Temp

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-25
Updated
2026-09-25

ATT&CK techniques

Execution → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule detects the Hancom HWP word processor spawning an executable file from the user AppData Local Temp directory, a behavior observed in an EDR-analyzed ransomware campaign delivered through malicious HWP documents. It captures the initial code-execution stage where a lure document drops and launches a payload leading to file encryption. Detecting this parent-child anomaly is important because office document processors should not launch arbitrary executables from temporary folders.

Related detections9 linkedT1204.002 — drag to rearrange
Malicious RoKRAT Staged Loader Files in Temp via LNK (via file_event)
Suspicious javaw.exe Executing JAR From Masqueraded Roaming Directory via Interlock Ransomware (via process_creation)
Malicious NailaoLocker Ransom Note and Encrypted File Creation (via file_event)
Malicious Ransom Note and Encrypted Extension via Hakuna Matata Variant (via file_event)
Malicious WPS Office ksoqing Protocol Handler Exploitation via Process Creation
Malicious Hunters International Ransomware Execution via rundll32
Suspicious mshta or wscript Spawned by Explorer via ClickFix Run Dialog (via process_creation)
Suspicious Double-Extension PDF JavaScript Lure via WScript (via process_creation)
Suspicious VBScript Execution from Public User Directory (via process_creation)
Malicious Ransomware Payload Execution via HWP Word Processor Spawning Executable from Temp
Pivot detection · T1204.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.