Kimsuky JSE Loader XML DOM base64 payload decode via wscript/cscript
This rule detects malicious activity associated with Kimsuky JSE loaders, which leverage XML DOM manipulation (e.g., bin.base64) and ADODB.Stream components to decode and drop base64-encoded payloads into the ProgramData directory. It further monitors for subsequent decoding attempts using certutil and the presence of specific, suspicious file extensions (e.g., .a9oc, .lpXD, .lpxQ) often used by this threat actor.
Microsoft Sentinel (KQL)

