Malicious Winlogon Shell Hijack Loading MSBuild

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects the Winlogon Shell value being altered to reference MSBuild which the Dark Pink APT uses to persist and proxy execute code at logon through a trusted developer binary. The Shell key should only launch explorer.exe so any MSBuild reference signals abuse. It matters because it combines stealthy persistence with signed binary proxy execution.

Related detections9 linkedT1127.001 — drag to rearrange
Proxy Execution via MSBuild Running Inline Task XML
MSBuild Executing Non-Project File or Remote Payload
Antivirus Check and Remote Loader Retrieval in LNK Command Chain
Suspicious MSBuild Execution From Office or Archive Extraction Context (via process_creation)
Malicious Winlogon Shell or Userinit Persistence Modification (via registry_set)
Suspicious Command Prompt Spawned by Winlogon
Suspicious Winlogon Loading Keyboard Layout DLL kbdus1.dll
Malicious Winlogon Shell Persistence Modification (via registry_set)
Suspicious MSBuild Execution from Writable Directory (via process_creation)
Malicious Winlogon Shell Hijack Loading MSBuild
Pivot detection · T1127.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.