Malicious TCP Session Hijacking via rshijack

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-08-14
Updated
2026-08-28

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects execution of the rshijack tool used to inject data into established TCP sessions. Wiz Research observed rshijack abused inside a shared Replicate environment to hijack traffic to a central Redis instance, so its use strongly indicates adversary in the middle or lateral movement activity.

Related detections9 linkedT1557 — drag to rearrange
Suspicious Windows Native Pktmon Sniffer Abuse (via process_creation)
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Suspicious Windows Traffic Capture Abuse (via process_creation)
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
Malicious EdgeStepper iptables DNS Redirection for Adversary-in-the-Middle
Suspicious Tycoon 2FA Credential Exfiltration Fields
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Suspicious Entra Sign-In Interrupt With High Aggregated Risk via AiTM DNS Hijacking (via azure)
Possible Adversary-in-the-Middle Proxy Login via Crafted URL Parameters
Malicious TCP Session Hijacking via rshijack
Pivot detection · T1557 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.