Suspicious ClickFix PowerShell Execution with Hidden Window (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects PowerShell launched with an abbreviated hidden window style argument combined with string reconstruction, a pattern used by ClickFix clipboard lures delivering MIMICRAT. Observed in Elastic Security Labs telemetry where powershell -WInDo Min hides the console while string-slicing rebuilds the attacker domain to fetch the custom RAT.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious Encoded PowerShell Execution with No Profile
Suspicious PowerShell Encoded Command Execution
Suspicious PowerShell BITS Transfer of DLL Payload via process_creation
Malicious Masquerading TiWorker Spawning PowerShell Downloader via process_creation
Suspicious Script Host Spawning PowerShell via Process Creation
Suspicious PIKABOT PowerShell Download to Public Directory via Process Creation
Malicious SQL Server Command Execution Spawning Download Utilities via Process Creation
Suspicious PowerShell Script Fetching Remote Batch File From Paste Site (via ps_script)
Suspicious PowerShell Download of Payload From Pastebin (via process_creation)
Suspicious ClickFix PowerShell Execution with Hidden Window (via process_creation)
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.