TinyLoader USB Propagation via Double-Extension Executables (via file_event)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-08-30
Updated
2026-08-30

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of double-extension executables such as Photo.jpg.exe and Document.pdf.exe used by TinyLoader to spread across removable media. Adversaries leverage deceptive filenames that appear to be images or documents so users execute the loader from infected USB drives.

Related detections4 linkedT1091 — drag to rearrange
Suspicious Process Execution From Recycle Bin Directory
Suspicious Removable Media Spread via My Pictures Executable (via process_creation)
Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
TinyLoader USB Propagation via Double-Extension Executables (via file_event)
Pivot detection · T1091 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.