COLDSTEEL RAT Anonymous User Process Execution
Detects the creation of a process executing as user called "ANONYMOUS" seen used by the "MileStone2016" variant of COLDSTEEL
Detection logic
selection
ParentImage|contains:
- \Windows\System32\
- \AppData\
User|contains: ANONYMOUSCondition
selectionRaw YAML
title: COLDSTEEL RAT Anonymous User Process Execution
id: e01b6eb5-1eb4-4465-a165-85d40d874add
status: test
description: Detects the creation of a process executing as user called "ANONYMOUS" seen used by the "MileStone2016" variant of COLDSTEEL
references:
- https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/cold-steel/NCSC-MAR-Cold-Steel.pdf
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-04-30
tags:
- attack.persistence
- detection.emerging-threats
- attack.stealth
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|contains:
- '\Windows\System32\'
- '\AppData\'
User|contains: 'ANONYMOUS'
condition: selection
falsepositives:
- Unknown
level: highFalse positives
- Unknown
References
Similar rules
APT27 - Emissary Panda Activity
criticalwindows · Same logsource category (process_creation)
COLDSTEEL RAT Cleanup Command Execution
criticalwindows · Same logsource category (process_creation)
COLDSTEEL RAT Service Persistence Execution
criticalwindows · Same logsource category (process_creation)
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
mediumwindows · Same logsource category (process_creation)