msgbox.exe recomputes Secure Preferences super_mac to install rogue extension

The detection rule identifies an suspicious process named 'msgbox.exe' attempting to interact with browser configuration files ('Secure Preferences') and activity directories ('stomp_ext'), while simultaneously invoking browser processes ('chrome.exe' or 'msedge.exe') with the '--restore-last-session' argument. This behavior is indicative of an adversary attempting to force-load a browser session or hijack browser state, potentially to steal session cookies or credentials.