Suspicious PowerShell Decoding Base64 Payload Stored in Registry

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-10
Updated
2026-10-10

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects PowerShell reading a value from the HKLM SOFTWARE\System key and base64 decoding it in memory. The ClipBanker loader stored a base64 PowerShell stage inside a registry Config value and used a scheduled task to decode and run it as documented by Kaspersky. Fileless retrieval of an encoded payload from the registry is a hallmark of staged, evasive execution.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious PowerShell WebClient UploadString Network Beacon
Suspicious Script Interpreter Spawned by mshta
Suspicious PowerShell Execution of AdobeMon Script with Bypass Policy
Suspicious PowerShell Execution Bypass Running Script From ProgramData
Suspicious cmd.exe Launching Encoded PowerShell From Shortcut File
Suspicious Cursor Editor Process Spawning PowerShell
Suspicious PowerShell Base64 Encoded Staged Downloader via process_creation
Suspicious GitVenom Visual Studio Pre-Build Event Shell Execution via process_creation
Malicious PowerShell UrlDecode Payload Spawned by SQL Server after FortiClient EMS Exploitation
Suspicious PowerShell Decoding Base64 Payload Stored in Registry
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.