APT 35 - Charming Kitten - G0059 — Magic Hound | Archive-lure phishing chain: extraction tool spawns scripting engine with network/encoded indicators
Detects execution chains where archive utilities (7-Zip, WinRAR) or explorer.exe, when initiated from temporary or download directories, spawn common scripting engines (PowerShell, mshta.exe, cmd.exe, wscript.exe) that contain suspicious network-related or obfuscated command-line indicators.
Microsoft Sentinel (KQL)

