MovieReaper Stage-3 Payload Masquerading as msedge.exe in Telemetry Folder
Detects execution of a process masquerading as msedge.exe located within the Windows Telemetry directory. This behavior is associated with the MovieReaper malware, specifically as a stage-3 payload activity following UAC bypass and persistence establishment.
YARA-L

