StealC persistence via h2dk2pdvpn0.lnk in Startup folder
Detects the creation of a specifically named shortcut (.lnk) file in the Windows Startup directory, a common persistence mechanism used by StealC/ClickFix malware variants.
YARA-L

Detects the creation of a specifically named shortcut (.lnk) file in the Windows Startup directory, a common persistence mechanism used by StealC/ClickFix malware variants.

Already have an account?