Suspicious Python Execution of Fake Sysmon Script From Config Directory

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-10-10
Updated
2026-10-10

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects a Python interpreter executing a sysmon.py script from a hidden .config/sysmon directory on Linux. The LiteLLM AI gateway supply-chain implant masqueraded as a sysmon service under ~/.config/sysmon and installed systemd persistence as reported by Kaspersky. Reusing the Windows Sysmon name for a Linux Python script in a user config path is a masquerading indicator of the backdoor.

Related detections9 linkedT1036.005 — drag to rearrange
Malicious systemd-daemon Masquerading Binary Execution on Linux
Suspicious vcpktsvr Loader Execution From LOCALAPPDATA vcpacket Directory
Suspicious Process Execution From Fake Microsoft Edge ExtSvc Directory
Suspicious kswapd0 Masquerading Miner Process
Suspicious msinfo32.exe Executed From ViPNet Update Directory
Malicious Desktop Window Manager Impersonation From Non-System Path via process_creation
Malicious Svchost Impersonation From Non-System Path via process_creation
Malicious RustyStealer Masquerading as AudioDriver in Windows Temp
Suspicious svchost Invocation with Non-Standard svcr Argument
Suspicious Python Execution of Fake Sysmon Script From Config Directory
Pivot detection · T1036.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.