HVNC backdoor masquerading as UpdateAssistant/AppUpdateHelper in AppData

Detects the execution of known Windows update-related binaries (UpdateAssistant.exe or AppUpdateHelper.exe) from non-standard, suspicious locations within AppData directories. This behavior is indicative of masquerading, where an adversary attempts to blend in by using a legitimate process name from an unexpected path.