Suspicious PowerShell Outlook COM Automation for Mail Access via TCLBANKER

PremiumReviewedSigma · Medium · v1
Product
windows
Category
ps_script
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects PowerShell attaching to a running Outlook instance through the COM automation interface as used by the TCLBANKER trojan to read victim mail in Elastic research. Using GetActiveObject on the Outlook Application object allows the malware to harvest messages and monitor the inbox for banking interactions.

Related detections6 linkedT1114 — drag to rearrange
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious AWS SES Production Access Request via PutAccountDetails (Cloud Email Abuse)
Microsoft 365 Threat Management: PST Export via New-ComplianceSearchAction -Export
Microsoft 365 eDiscovery PST Export or Search Started Success Alert
Windows Process Creation: Exchange PowerShell Snap-in Loading via Add-PSSnapin
Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Suspicious PowerShell Outlook COM Automation for Mail Access via TCLBANKER
Pivot detection · T1114 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.