Rule Info
Name
Tiny C Compiler Runtime Execution
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects execution of Tiny C Compiler (TCC) which compiles and executes C code directly in memory.
This technique was observed in Chrysalis backdoor campaigns where attackers renamed tcc.exe to svchost.exe and used it
to load shellcode from .c files directly into memory, bypassing traditional detection methods.
Reference
Date
2026-02-03 00:00:00
Modified
None
Id
8a3b5d2e-7f4c-4e9a-b1d6-3c8e5f2a9b4d
Tags
attack.defense-evasion attack.execution attack.t1059 attack.t1027.004
Type
Nextron Sigma feed only (private)
