Turla STOCKSTAY - HTA Lure Execution from Archive via mshta.exe
Detects mshta.exe spawning from archive utilities (winrar.exe, 7z.exe) or Windows Explorer, or executing HTA files directly from common user-writable temporary or download directories. This pattern is commonly associated with the execution of malicious payloads delivered via compressed archives, a technique observed in campaigns attributed to the Turla threat group.
Microsoft Sentinel (KQL)

