Malicious Viper C2 Installation via f8x One-Liner Setup Script (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-07-23
Updated
2026-08-28

ATT&CK techniques

Resource Dev
  1. Recon

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects execution of the f8x offensive setup script used by the You Dun group to deploy Viper command-and-control tooling on Linux staging hosts, invoked through bash with flags such as -viper or -all. The f8x helper is an attacker-specific installer for red-team infrastructure, so its execution on a server is a high-confidence indicator of adversary tooling being stood up rather than legitimate administration.

Related detections9 linkedT1588.002 — drag to rearrange
Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution
Windows Registry: Sysinternals Renamed Tool Execution Indicator via EulaAccepted Key
Windows Hacktool Execution via PE Metadata Company Field
Windows Hacktool Execution Flagged by Imphash in Process Creation
Windows Suspicious File Downloads from Outlook/OneNote Attachment Domains via Command-Line
Windows: Renamed Sysinternals DebugView Process Execution
Windows Registry: Suspicious Keyboard Layout Preload in User Session
Windows Registry Key Created: Sysinternals EULA Acceptance
Malicious Viper C2 Installation via f8x One-Liner Setup Script (via process_creation)
Pivot detection · T1588.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.