SStar Agent Windows Persistence via Startup Folder
Detects the creation or modification of an executable named 'GoogleUpdateService.exe' within a user's Windows Startup folder. This activity is indicative of the SStar Agent malware establishing persistence, as it masquerades as a legitimate Google update service but uses an atypical persistence mechanism (Startup folder instead of Scheduled Tasks or Registry Run keys).
Microsoft Sentinel (KQL)

