T1027/T1059.001: Kimsuky GitPower LNK-Spawned Obfuscated PowerShell Payload
Detects execution of PowerShell or CMD initiated by the Kimsuky GitPower loader. The rule identifies suspicious command-line artifacts including excessive character padding (leading spaces), extremely long command lines, and the presence of a hardcoded, unique base64 decoding variable ('$VIUSBvejbawf') associated with this specific malware family.
YARA-L

