Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-07-30
Updated
2026-08-28

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Priv Esc

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects the hardcoded kill-switch string used by the XZ Utils liblzma backdoor (CVE-2024-3094) appearing in process command lines or environment variables. The backdoor checks for this specific token to disable itself, and its presence in telemetry indicates interaction with the implanted malicious code. Investigating hosts exhibiting this string helps identify systems affected by the supply chain attack.

Related detections9 linkedT1059.004 — drag to rearrange
Malicious Shell Payload Piped from curl to zsh
Possible Bitbucket Pre-Auth RCE via git archive exec Null-Byte Injection (CVE-2022-36804) (via webserver)
Malicious TeamTNT Docker Gatling Gun Initialization Script (via process_creation)
Suspicious Shell Spawned by PostgreSQL Server Process (via process_creation)
Malicious Remote Script Piped Directly to a Shell (via process_creation)
HamsaUpdate Linux Payload Download via Wget Piped to Bash (via process_creation)
Malicious TeamPCP systemd User Unit Dropper via sysmon.py Persistence (via file_event)
Suspicious Python Startup .pth File Creation for Interpreter Persistence
Suspicious Remote Script Execution via Wget or Curl Piped to Shell (via process_creation)
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.