Suspicious Ransom Note Delivery via Legal Notice Registry Values

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule detects modification of the Winlogon legalnoticecaption or legalnoticetext policy values. The Ymir ransomware set these logon banner values to display its ransom message at sign-in, so unexpected changes outside managed policy can indicate ransomware impact.

Related detections4 linkedT1491.001 — drag to rearrange
Windows Registry Change to Desktop Wallpaper Policy or Settings
Windows reg.exe Changes Desktop Background Policy Values
Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Windows PowerShell Wallpaper Replacement via Registry and SystemParametersInfo
Suspicious Ransom Note Delivery via Legal Notice Registry Values
Pivot detection · T1491.001 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.