Suspicious Removable Media Spread via My Pictures Executable (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-06-23
Updated
2026-08-28

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects execution of a binary named My Pictures.exe which VenomRAT copies onto removable drives to spread across hosts in the RevengeHotels campaign. The lure name mimics a familiar folder to trick users into launching it from a USB device. An executable using this decoy name is indicative of USB-based propagation.

Related detections4 linkedT1091 — drag to rearrange
TinyLoader USB Propagation via Double-Extension Executables (via file_event)
Suspicious Process Execution From Recycle Bin Directory
Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
Suspicious Removable Media Spread via My Pictures Executable (via process_creation)
Pivot detection · T1091 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.