Suspicious Aimmy Cheat Loader Executing Renamed LuaJIT Launcher via process_creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-06-27
Updated
2026-08-28

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule detects the trojanized Aimmy game cheat that uses Aimmy.bat to launch AimmyLauncher.exe, a renamed LuaJIT interpreter which executes malicious Lua bytecode. The threat abuses a signed scripting engine to run attacker supplied Lua while posing as a gaming aimbot. Flagging the batch launcher and the renamed interpreter surfaces the living off scripting execution chain before the bytecode payload runs.

Related detections9 linkedT1105 — drag to rearrange
Malicious SCMBanker ClickFix Payload Fetch via Curl Piped to Cmd
Suspicious Payload Download to Temp Masquerading as System32 File (via process_creation)
Suspicious Cmd Using Curl to Download and Execute Payload (via process_creation)
Malicious LOLBin Download Saved as Windows Utility ping.exe via certutil or curl
Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Windows Process Execution: Suspicious cmd.exe Command-Line Combinations (Pikabot-like)
Windows: Process executions matching Greenbug espionage tool indicators
Windows cmd.exe Command Line with URL and %AppData% Indicators
Suspicious Remote HTA Payload Execution via MSHTA
Suspicious Aimmy Cheat Loader Executing Renamed LuaJIT Launcher via process_creation
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.