Suspicious tmp Download and Execute Chain on Embedded Linux

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects a shell chain that changes into the tmp directory fetches a payload with wget grants it full permissions with chmod and executes it which is the classic Mirai infection sequence on DVR and IoT devices. This variant uses it to deploy an ARM Mirai bot after exploiting CVE-2024-3721. The download and chmod and execute pattern in tmp is a strong IoT botnet indicator.

Related detections9 linkedT1059.004 — drag to rearrange
Suspicious Bash Dev-TCP Reverse Shell Execution
Malicious Remote Script Piped to Shell via Curl (via process_creation)
Suspicious Downloaded Shell Stager Made Executable Via Chmod 777
Malicious Remote Script Piped Directly to a Shell (via process_creation)
HamsaUpdate Linux Payload Download via Wget Piped to Bash (via process_creation)
Malicious Curl to Shell Dropper from Paste Site via Command Line
Malicious kagent RAT Delivery via HuggingFace Space Download (via process_creation)
Suspicious Remote Script Execution via curl Piped to bash with nohup on macOS (via process_creation)
Suspicious Botnet Payload Drop to Hidden Xdiag Temp Path
Suspicious tmp Download and Execute Chain on Embedded Linux
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.