APT41 ToughProgress LNK Spearphish - Explorer Spawning Rundll32 with Image Payload

Detects the execution of rundll32.exe initiated by explorer.exe where the command line references common user folders (AppData, Temp, Downloads) and includes suspicious file extensions (e.g., images, PDFs, Office docs). This pattern is often indicative of malicious code execution where an adversary uses rundll32.exe to proxy execution of payloads masked as benign files.