Suspicious Execution From var tmp Masquerading as apt via GRIDTIDE

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-07-29
Updated
2026-08-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a binary named xapt executing from the var tmp directory as used by the GRIDTIDE espionage campaign to masquerade as the legitimate apt package manager. Attackers run this payload with root privileges to spawn shells and establish backdoor access.

Related detections9 linkedT1059.004 — drag to rearrange
Malicious Shell Payload Piped from curl to zsh
Possible Bitbucket Pre-Auth RCE via git archive exec Null-Byte Injection (CVE-2022-36804) (via webserver)
Malicious Fake Fortinet Patch Infostealer Execution (via process_creation)
Malicious TeamTNT Docker Gatling Gun Initialization Script (via process_creation)
Suspicious Shell Spawned by PostgreSQL Server Process (via process_creation)
Suspicious Masquerading Python Interpreter csshost Executing Script
Malicious Remote Script Piped Directly to a Shell (via process_creation)
FortiClient Binary Executed from LocalAppData Compliance Directory (via process_creation)
Masquerading Edge Update Masquerade Executed From AppData (via process_creation)
Suspicious Execution From var tmp Masquerading as apt via GRIDTIDE
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.