Operation DragonReturn: Steganographic JPEG Payload Download to C:\Windows\
Detects the download of potential steganographic image files (specifically .jpg extensions) from known malicious IP addresses, followed by the creation of a non-Microsoft-signed image file in the C:\Windows directory by the same process storyline. This behavior suggests the download and extraction of an embedded malicious payload.
SentinelOne

