Detection of Renamed Python Binaries for Defense Evasion
Adversaries are masquerading as legitimate processes by renaming Python binaries to evade security controls and execute malicious payloads on Windows endpoints.
What's new
- 1. OS windows Oct 6, 12:03 via splunk-escu
Security analysts have identified an increase in defense evasion tactics where threat actors rename the standard Python interpreter executable (e.g., python.exe, pythonw.exe) to an arbitrary name before execution on Windows systems. By masquerading as a different process, attackers attempt to bypass application allowlisting, directory-based execution restrictions, and behavior-based alerts that rely on process names.
This activity has been observed in conjunction with the distribution of Python-based Remote Access Trojans (RATs), where attackers package malicious scripts with the renamed interpreter to ensure their execution within a target environment. Defenders should monitor for discrepancies between the process image name and the original file name metadata attribute, which remains populated in PE headers even when the file is renamed on disk. This activity is a key indicator of masquerading and should be treated as a potential sign of unauthorized code execution or persistence mechanism deployment.
Attack Chain
- Attacker identifies a target Windows system for code execution.
- Attacker drops a legitimate Python interpreter binary onto the system.
- Attacker renames the Python binary (e.g., 'python.exe' to 'svchost.exe' or 'svchost_v2.exe') to blend in with legitimate system processes.
- Attacker deploys a malicious Python script or library alongside the renamed binary.
- Attacker executes the renamed binary with arguments pointing to the malicious script.
- EDR telemetry captures the process creation event, showing a mismatch between the renamed 'process_name' and the original 'original_file_name' metadata.
- The process establishes a connection to C2 infrastructure to download additional payloads or exfiltrate data.
- Malicious Python-based RAT operates in memory to perform the final objective.
Impact
Successful execution allows attackers to maintain persistence, execute unauthorized code, and evade process-based monitoring. Observed instances involve Python-based RATs being used to gain full remote control of compromised Windows workstations and servers, leading to potential data theft and lateral movement within the network.
Recommendation
Deploy detection rules to identify process name mismatches specifically targeting the Python interpreter suite.
- Enable EDR telemetry capturing
original_file_namemetadata as provided by Sysmon Event ID 1 or equivalent process creation logs. - Implement the Sigma rule provided below to monitor for process renaming behavior.
- Investigate endpoints generating alerts for renamed binaries, focusing on the parent process lineage and any associated network activity initiated by the renamed process.
- Ensure that the
Processesnode of theEndpointdata model is populated and that telemetry is correctly normalized using the Common Information Model (CIM).
Immediate actions
Deploy the 'Detect Renamed Python Binary Execution' Sigma rule to SIEM.
Threat Hunt
Search for process creation events where OriginalFileName contains 'python' and process_name is not 'python.exe' or 'pythonw.exe'.
Data: Sysmon EID 1
Detection coverage 1
Detect Renamed Python Binary Execution
mediumDetects execution of a process where the process name does not match the original file name, specifically targeting Python interpreter variants.
Detection queries are available on the platform. Get full rules →