Suspicious Downloader Writing to Public Libraries Directory

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects download utilities such as bitsadmin, certutil, or curl retrieving files into the Public Libraries directory, a staging location used by the Tomiris APT. The actors fetched Havoc and AdaptixC2 payloads into $public\libraries to blend with rarely inspected shared folders. Using a download LOLBin to write into the Public user profile is a strong indicator of ingress tool transfer for later execution.

Related detections9 linkedT1105 — drag to rearrange
Suspicious Reconnaissance and Payload Download by Node Web Process
Suspicious Process Execution From Windows Tasks Directory
Suspicious Execution From Hidden fonts-unix Directory in tmp on Linux
Suspicious tmp Download and Execute Chain on Embedded Linux
Suspicious Curl Download to Update Executable during FortiClient EMS Exploitation
Suspicious File Download via certutil urlcache
Suspicious PowerShell Download from Public Content Hosting via BlindEagle
Malicious Geacon Payload Download to Temp via Trojanized Editor (via process_creation)
Suspicious osascript Spawning Shell curl to External Host on macOS (via process_creation)
Suspicious Downloader Writing to Public Libraries Directory
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.