BaoLoader Drive-By: Browser Drop to TEMP/APPDATA then cmd/PowerShell Spawn
Detects potential BaoLoader drive-by compromise attempts by monitoring two stages: first, the creation of executable files in temporary or application data directories by browser processes; and second, the execution of command-line shells by processes running from those same directories where the browser acted as the grandparent.
SentinelOne

