Malicious ViPNet Backdoor Loader via lumpdiag.exe Path Substitution

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects lumpdiag.exe being started with the --msconfig argument that triggers path substitution to load a malicious msinfo32.exe from the ViPNet update directory. This behavior is used by a backdoor masquerading as ViPNet secure networking software updates against Russian organizations to achieve execution through a trusted binary. Detecting it exposes the DLL/binary search-order hijack that bootstraps the loader chain.

Related detections9 linkedT1574.001 — drag to rearrange
Suspicious Extexport DLL Side-Loading Execution
Malicious CiscoCollabHost Execution From AppData Path via process_creation
Suspicious msinfo32.exe Executed From ViPNet Update Directory
Suspicious DLL Side-Loading Host Binary Executed Outside System32 by Lazarus
Suspicious BitLockerToGo Execution from Unusual Parent
Suspicious Proxy Execution via pcalua
Suspicious RC4 DLL Sideloading via rundll32 by Tropic Trooper
Malicious DLL Sideloading via Renamed Signed Binary PlayVideoFull (via process_creation)
Suspicious obs-browser-page.exe Executing Outside OBS Installation Path (via process_creation)
Malicious ViPNet Backdoor Loader via lumpdiag.exe Path Substitution
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.