BeepRAT Persistence via WindowsUpdateTempFileCleanUp Scheduled Task
Detects the BeepRAT malware establishing persistence by creating a scheduled task named 'WindowsUpdateTempFileCleanUp' via 'schtasks.exe'. The task is configured to execute a malicious loader chain using the Tiny C Compiler to run a hidden config file, often spawned from a binary named 'HFY.exe'.
Sigma

