HVNC Keylogger API YARA Hit Combined with Unsigned Binary in AppData

This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.