BabylonRAT Persistence via Fake Firefox Autorun Registry Key
Detects instances where a process named firefox.exe attempts to modify or create a registry run key, which is a common persistence technique, but the process file path does not correspond to the legitimate Mozilla Firefox installation directory. This behavior often indicates that an attacker is masquerading as a legitimate browser process to establish persistence.
SentinelOne

