TinyLoader Persistence via txtfile Shell Open Command Hijack (via registry_set)

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-07-25
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects modification of the txtfile shell open command handler so that opening any text file first launches an attacker binary, the file-association hijack TinyLoader uses for persistence. Adversaries leverage this handler so the loader runs whenever a user opens a .txt file, then still opens the file to avoid suspicion.

Related detections4 linkedT1546.001 — drag to rearrange
Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Windows: assoc.exe Changes File Extension Handler to exefile
Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Windows Process: File Association Changes via assoc Command
TinyLoader Persistence via txtfile Shell Open Command Hijack (via registry_set)
Pivot detection · T1546.001 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.