NPM crypto-stealer/RAT campaign C2 connections (Aug 2026)

This rule monitors DeviceNetworkEvents for outbound connections to specific known malicious IP addresses (31.97.137.157 and 46.183.25.232) on port 45000, or connections to the domain 'bet.slotgambit.com'. These indicators are consistent with command and control (C2) activity.