Suspicious FakeBat Fake Browser Update Stats and Download Endpoints (via proxy)

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-06-05
Updated
2026-08-28

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects requests to the FakeBat distribution endpoints get_stats.php and the misspelled dwnl_standart.php used by fake browser update pages to track victims and serve the MSIX payload. The typo-laden download path is a distinctive campaign artifact hosted on doggygangers[.]com. This surfaces drive-by delivery of FakeBat leading to LummaC2.

Related detections6 linkedT1189 — drag to rearrange
Suspicious Connection to Local Zoom Opener Webserver Launch Endpoint (via network_connection)
Suspicious macOS Installer Invocation Spawned via Zoom Opener Helper (via process_creation)
Suspicious Watering Hole Exfiltration to Fake wp-includes Endpoint via SilentSelfie
Suspicious Child Processes Spawned by Browsers on macOS
Webserver GET requests containing XSS-related payload strings
Proxy Web Requests for Flash Player Installer from Unofficial Locations
Suspicious FakeBat Fake Browser Update Stats and Download Endpoints (via proxy)
Pivot detection · T1189 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.