APT36 Scheduled Task Masquerading as Edge Updater Runs Encoded PowerShell

Detects malicious scheduled task creation using names associated with Microsoft Edge updates, or the execution of PowerShell commands that utilize encoded arguments and known APT36 download cradles, indicating an attempt to establish persistence or retrieve secondary payloads.