Suspicious wscript Execution of MicrosoftEdgeUpdate VBS Masquerade

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the Windows Script Host running a script named MicrosoftEdgeUpdate.vbs. The Cloud Atlas group used a VBS masquerading as a Microsoft Edge updater executed through wscript as described by Kaspersky. Genuine Edge updates do not run a VBScript by this name so execution through the script host indicates masquerading and malicious script execution.

Related detections9 linkedT1059.005 — drag to rearrange
Suspicious wscript Executing Single-Letter VBS Loader
Suspicious WScript Execution of VBS from NTFS Alternate Data Stream by Cloud Atlas
Suspicious Script Execution of Disk.vbs from Templates Directory (via process_creation)
Suspicious AutoIt3 Execution With Compiled Script Argument via Process Creation
Suspicious VBScript Persistence in CurrentVersion Run Key
Suspicious VBScript Code Stored in CurrentVersion Registry Value
Suspicious VBScript Payload Stored in CurrentVersion Registry Value (via registry_set)
Suspicious rundll32 or mshta Proxy Execution of VBScript
Suspicious Office Application Spawning Script Interpreter
Suspicious wscript Execution of MicrosoftEdgeUpdate VBS Masquerade
Pivot detection · T1059.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.