Suspicious Sang Loader Execution with Install or PassUAC Arguments

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the Sang.exe loader executing with its install, work or passuac operation arguments. HoneyMyte used Sang.exe with these command modes to install the CoolClient implant and bypass user account control as described by Kaspersky. Execution of this loader with these mode arguments indicates implant installation and privilege escalation.

Related detections9 linkedT1055 — drag to rearrange
Suspicious GodRAT Shellcode Injection via Puppet Argument (via process_creation)
Suspicious Executable Execution From AppData Roaming msgui via Process Creation
Suspicious RuntimeBroker Network Connection via Loki Mythic Agent
Suspicious Network Connection from mspaint or msiexec (via network_connection)
Suspicious DLL Hijack via BugSplatRc64 Sideloading (via image_load)
Suspicious Rundll32 Execution Without Arguments
Malicious Quantum Ransomware ttsel Payload Execution via Command Line
Malicious PowerShell Runtime Loaded Outside PowerShell Host
Suspicious App Domain Manager Injection via Environment Variables
Suspicious Sang Loader Execution with Install or PassUAC Arguments
Pivot detection · T1055 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.