Malicious Remote Payload Piped to Shell via Curl or Wget

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-05-16
Updated
2026-08-28

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects download utilities piping fetched content directly into a shell interpreter, the loader pattern the agentic container-escape actor used to stage its second-stage payload from an attacker server. Piping remote content into sh or bash executes untrusted code without touching disk. This is a common ingress tool transfer and execution technique.

Related detections9 linkedT1105 — drag to rearrange
Suspicious Bash Reverse Shell via /dev/tcp
Windows Autoit3.exe Created by Uncommon Process (curl.exe/KeyScramblerLogon.exe/etc.)
Suspicious Remote HTA Payload Execution via MSHTA
Possible PurpleFox MSHTA to Msiexec Remote MSI Chain
MSBuild Executing Non-Project File or Remote Payload
Antivirus Check and Remote Loader Retrieval in LNK Command Chain
Suspicious PowerShell Hidden Web Download via Invoke-WebRequest by CatB Ransomware
Possible Ivanti Pulse Connect Secure Command Injection via License Keys-Status Endpoint (via webserver)
Possible Craft CMS RCE via Query-String CLI Option Injection
Malicious Remote Payload Piped to Shell via Curl or Wget
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.