Malicious Simps Botnet Infection Marker File Creation (via file_event)

PremiumReviewedSigma · High · v1
Product
linux
Category
file_event
Author
HuntRule
Published
2026-07-23
Updated
2026-08-28

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule detects creation of the keksec.infected.you.log marker file dropped by the Simps botnet to flag a compromised host. The presence of this Keksec group artifact indicates the device has been enrolled into Mirai and Gafgyt based DDoS operations.

Related detections3 linkedT1498 — drag to rearrange
Kubernetes Deployment Deleted via Kubernetes API Audit Logs
OpenCanary NTP Monlist Request Observed
Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Malicious Simps Botnet Infection Marker File Creation (via file_event)
Pivot detection · T1498 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.