Skip to content
Threat Feed
medium advisory updated

Detection of Renamed Python Binaries for Defense Evasion

Adversaries are masquerading as legitimate processes by renaming Python binaries to evade security controls and execute malicious payloads on Windows endpoints.

What's new

Security analysts have identified an increase in defense evasion tactics where threat actors rename the standard Python interpreter executable (e.g., python.exe, pythonw.exe) to an arbitrary name before execution on Windows systems. By masquerading as a different process, attackers attempt to bypass application allowlisting, directory-based execution restrictions, and behavior-based alerts that rely on process names.

This activity has been observed in conjunction with the distribution of Python-based Remote Access Trojans (RATs), where attackers package malicious scripts with the renamed interpreter to ensure their execution within a target environment. Defenders should monitor for discrepancies between the process image name and the original file name metadata attribute, which remains populated in PE headers even when the file is renamed on disk. This activity is a key indicator of masquerading and should be treated as a potential sign of unauthorized code execution or persistence mechanism deployment.

Attack Chain

  1. Attacker identifies a target Windows system for code execution.
  2. Attacker drops a legitimate Python interpreter binary onto the system.
  3. Attacker renames the Python binary (e.g., 'python.exe' to 'svchost.exe' or 'svchost_v2.exe') to blend in with legitimate system processes.
  4. Attacker deploys a malicious Python script or library alongside the renamed binary.
  5. Attacker executes the renamed binary with arguments pointing to the malicious script.
  6. EDR telemetry captures the process creation event, showing a mismatch between the renamed 'process_name' and the original 'original_file_name' metadata.
  7. The process establishes a connection to C2 infrastructure to download additional payloads or exfiltrate data.
  8. Malicious Python-based RAT operates in memory to perform the final objective.

Impact

Successful execution allows attackers to maintain persistence, execute unauthorized code, and evade process-based monitoring. Observed instances involve Python-based RATs being used to gain full remote control of compromised Windows workstations and servers, leading to potential data theft and lateral movement within the network.

Recommendation

Deploy detection rules to identify process name mismatches specifically targeting the Python interpreter suite.

  • Enable EDR telemetry capturing original_file_name metadata as provided by Sysmon Event ID 1 or equivalent process creation logs.
  • Implement the Sigma rule provided below to monitor for process renaming behavior.
  • Investigate endpoints generating alerts for renamed binaries, focusing on the parent process lineage and any associated network activity initiated by the renamed process.
  • Ensure that the Processes node of the Endpoint data model is populated and that telemetry is correctly normalized using the Common Information Model (CIM).

Immediate actions

Deploy the 'Detect Renamed Python Binary Execution' Sigma rule to SIEM.

Detection Engineering 48h

Threat Hunt

Search for process creation events where OriginalFileName contains 'python' and process_name is not 'python.exe' or 'pythonw.exe'.

T1036.003 high high confidence hunt now

Data: Sysmon EID 1

Detection coverage 1

Detect Renamed Python Binary Execution

medium

Detects execution of a process where the process name does not match the original file name, specifically targeting Python interpreter variants.

sigma tactics: defense_evasion techniques: T1036.003, T1059.006 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →