ShroudCloud released a set of Windows Sigma detections focused on ransomware operators’ use of native lateral-movement primitives: WMI, Task Scheduler, Service Control Manager, WinRM, SMB, and RDP. Its highest-priority experimental correlation identifies a target receiving activity from two or more remote-execution methods within 60 seconds—a pattern associated with automated ransomware spread modules, including activity attributed to TheGentlemen. Supporting rules detect anonymous SMB share staging through null-session configuration changes, remote schtasks execution, WMI process creation, WinRM-launched living-off-the-land binaries, and remote scheduled-task creation via WinRM.
The detection set also covers precursor and follow-on behaviors commonly seen in ransomware intrusions: burst endpoint and domain enumeration, clustered suspicious commands across hosts, Windows Defender tampering, LSASS dumping through comsvcs.dll, Volume Shadow Copy manipulation, and scripted WinSCP transfers that may support exfiltration. Organizations should correlate source and target telemetry rather than rely on tool names, prioritize rapid multi-primitive activity as a potential ransomware-in-progress condition, and baseline sanctioned administration, fleet-management tools, backup jobs, and enterprise file-transfer workflows to reduce false positives.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
ShroudCloud published the experimental “Per-Target Primitive Co-occurrence (Ransomware Spread - Module Signature)” Sigma correlation rule. It triggers when two or more of WMI, Task Scheduler, SCM, and WinRM indicators occur against the same target host within 60 seconds.
ShroudCloud published the experimental “Anonymous Share Staging (Null-Session Payload Pull)” Sigma rule for a pattern attributed to TheGentlemen activity. It detects anonymous-share permission grants, null-session registry changes, and broadly accessible share creation, and recommends correlation of multiple signals within 120 seconds.
ShroudCloud published the experimental, high-severity “Native schtasks Remote Task Creation with UNC Target” Sigma rule. It detects schtasks.exe /S remote-task creation when paired with SYSTEM execution or a UNC-path task command.
ShroudCloud published “Operator Playbook Part 1,” identifying WMI, Task Scheduler, SCM, WinRM, RDP/SSH, and SMB staging as principal Windows ransomware movement mechanisms. It highlighted TheGentlemen’s reported parallel use of multiple execution primitives and recommended per-target correlation within 60 seconds.
ShroudCloud published the stable “Clustered Endpoint Enumeration” Sigma correlation rule. The rule detects more than one qualifying discovery command on a host within 10 minutes to identify burst-style endpoint and domain reconnaissance.
ShroudCloud published the experimental, critical-severity “Clustered Suspicious Process Creation Across Multiple Hosts” correlation rule. It flags at least three suspicious process events by one user across two or more hosts within 30 minutes.
ShroudCloud published the stable, high-severity “Remote Scheduled Task Creation via WinRM” Sigma rule. It detects suspicious chains in which unverified WinRM host processes spawn schtasks.exe with task-management arguments.
ShroudCloud published the stable, high-severity “Shadow Copy Access via LOLbin Parents” Sigma rule. It detects suspicious LOLBin activity involving shadow-copy deletion or access, credential extraction, and recovery inhibition.
ShroudCloud published the stable, high-severity “WMI Remote Process Execution via Native Binaries” Sigma rule. The rule detects wmic.exe /node process-call-create usage and remote Invoke-WmiMethod or Invoke-CimMethod commands targeting Win32_Process.Create.
ShroudCloud published the stable, high-severity “Remote Execution via WinRM Abuse” Sigma rule. It detects wsmprovhost.exe or winrshost.exe spawning selected reconnaissance, persistence, credential-access, or execution binaries.
ShroudCloud published the stable, high-severity “LSASS Memory Dump via Comsvcs.dll” Sigma rule. It detects rundll32.exe invoking comsvcs.dll to dump LSASS memory, including command lines containing comsvcs.dll and lsass or lsass.dmp.
ShroudCloud published the stable Sigma rule “Windows Defender Tampering via PowerShell,” which detects PowerShell and DISM attempts to disable Defender monitoring, add exclusions, or disable the Defender feature. The rule is mapped to MITRE ATT&CK T1562.001 and rated medium severity.
eSentire TRU reported that Hunters International used WinSCP as a fallback data-exfiltration mechanism when Rclone was its primary tool. The reporting described operators potentially pivoting to WinSCP when network controls block Rclone cloud-sync traffic.
ShroudCloud presented a stable Windows process-creation rule for detecting scripted or automated WinSCP transfers via command-line arguments and transfer commands. The rule is intended to identify potential ransomware-related exfiltration while accounting for legitimate scheduled enterprise file transfers.
ShroudCloud updated its detection-engineering analysis of ransomware lateral movement on Windows. The analysis continued to frame detection around six operating-system primitives rather than specific tools.
ShroudCloud published a detection-engineering analysis that organizes ransomware lateral movement around six Windows primitives: WMI, Task Scheduler, SCM, WinRM, RDP, and SMB. The analysis emphasizes detecting primitive-level artifacts rather than attacker-specific tool wrappers.
Sophos analyzed 413 selected incident-response and managed detection-and-response cases handled in 2024 for its Active Adversary Report. The dataset found compromised credentials, exploited vulnerabilities, and brute force to be leading intrusion causes, while ransomware accounted for 40% of combined cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
15 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourceshroudcloud.io
Open sourceshroudcloud.io
Open sourceshroudcloud.io
Open sourceshroudcloud.io
Open sourceshroudcloud.io
Open sourceshroudcloud.io
Open sourcenews.sophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.