Suspicious Python Script Persistence in User Startup Folder

PremiumReviewedSigma · Medium · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects a Python script being written into the Windows Startup folder. The Arkanix stealer establishes persistence by dropping hvnc.py into Startup so its hidden VNC module relaunches at logon as documented by Kaspersky. A .py file placed in Startup is highly unusual for legitimate software and indicates script-based autostart persistence.

Related detections9 linkedT1547.001 — drag to rearrange
Suspicious HealthApp Batch File Persistence in Start Menu Startup Folder
Suspicious FatalRAT Run Key Persistence to ProgramData Loader (via registry_set)
Suspicious VBScript Persistence in CurrentVersion Run Key
Malicious Sibot Malware Registry Persistence Value
Suspicious Run Key Persistence in CurrentVersion (via registry_set)
Suspicious Run Key Persistence Referencing Script Files Linked to FIN7
Suspicious LNK Persistence Dropped in Startup Folder
Suspicious LNK File Created In Startup Folder For Persistence
Suspicious cmd.exe Spawned by python.exe (via process_creation)
Suspicious Python Script Persistence in User Startup Folder
Pivot detection · T1547.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.