Suspicious SCMBanker Toolkit Staging via Bitsadmin to Public Directory

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects bitsadmin transferring a remote file into the world-writable C\Users\Public directory which SCMBanker uses to stage its fraud toolkit after initial access. Living-off-the-land BITS transfers evade download monitoring and blend with legitimate update traffic. The public staging path is a strong indicator of malicious payload delivery.

Related detections9 linkedT1105 — drag to rearrange
Suspicious DLL Download to ProgramData via Start-BitsTransfer (via process_creation)
Suspicious Remote Script Transfer via Bitsadmin (via process_creation)
Suspicious File Download Via Bitsadmin Transfer
BITS Payload Downloaded via Commandline (via process_creation)
BITS Payload Downloaded via PowerShell (via powershell)
Suspicious sLoad Payload Download via BITSAdmin LOLBin Transfer (via process_creation)
Suspicious File Download via Certutil URLCache
Windows Process Creation: bitsadmin Downloads Files to Suspicious Directories
Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension
Suspicious SCMBanker Toolkit Staging via Bitsadmin to Public Directory
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.