Luna Moth Callback Phishing: RMM Tool Spawned by Browser or Email Client

Detects the execution of known remote access and monitoring software (RMM/RAT) when launched as a child process of common web browsers or email clients. This behavioral pattern is frequently observed in phishing attacks where users are tricked into downloading and executing remote support tools, a technique often associated with the Luna Moth (Silent Ransom Group) campaign.