Malicious Registry Run Key Persistence Masquerading as MicrosoftUpdate

PremiumReviewedSigma · High · v1
Category
registry_set
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Priv Esc
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects creation of a HKCU Run value named MicrosoftUpdate, a masquerading persistence name planted by the compromised axios npm package RAT. The malware writes this autorun entry to relaunch a dropped script at logon while posing as a legitimate Microsoft component. A user-hive Run key using this Microsoft-lookalike name is a strong persistence indicator for this supply chain RAT.

Related detections9 linkedT1547.001 — drag to rearrange
Suspicious Node.js Spawning Script Interpreter for Dropped Payload
Malicious Node.js Execution of Hidden .claude Setup Script
Malicious axios NPM Supply Chain C2 Domain Resolution
Malicious Run Key Persistence Referencing DLL in User Documents
PlugX Persistence via Run Key Named AAM Updatevlm
Suspicious Autorun Registry Persistence via sausageLoop Run Key
Malicious BabyLockerKZ Run Key Persistence
Suspicious Run Key Persistence Pointing To User-Writable Path
Malicious Ctrlpanel Run Key Autostart Persistence (via registry_set)
Malicious Registry Run Key Persistence Masquerading as MicrosoftUpdate
Pivot detection · T1547.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.