Suspicious RuntimeBroker Network Connection via Loki Mythic Agent

PremiumReviewedSigma · Medium · v1
Product
windows
Category
network_connection
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Priv Esc → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects RuntimeBroker.exe initiating outbound network connections to non-local addresses, an anomaly produced when the Loki Mythic agent injects its gTunnel or ngrok tunneling code into runtimebroker and svchost host processes. RuntimeBroker is a local COM broker that should not talk to remote hosts, so external traffic from it points to injected C2 tunneling.

Related detections9 linkedT1071.001 — drag to rearrange
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious netsh Outbound Network Connection from IDAT Loader Injection
Suspicious Outbound Network Connection from Windows Dialer Process
Suspicious Excel Outbound Network Connection
Suspicious Network Connection from mspaint or msiexec (via network_connection)
Suspicious DLL Hijack via BugSplatRc64 Sideloading (via image_load)
Suspicious MgBot Marker Files Created in ProgramData Microsoft Folders
Suspicious DGA Subdomain Resolution of systemupdate.info by BellaCPP
Suspicious FatalRAT C2 HTTP Initial Submission Request (via proxy)
Suspicious RuntimeBroker Network Connection via Loki Mythic Agent
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.