RtkNGUI64.exe creates 8-character hex mutex matching CRC-32 beacon ID pattern
Detects RtkNGUI64.exe creating a mutex named as an 8-character hex string, consistent with the backdoor's CRC-32(USERNAME+USERDOMAIN+COMPUTERNAME) per-victim beacon ID used for single-instance checking.
Microsoft Sentinel (KQL)

