LausivLoader hidden PowerShell via conhost.exe --headless
Detects the execution of PowerShell with hidden flags and encoded commands spawned by a 'conhost.exe' process running in '--headless' mode. This specific process pattern is indicative of the obfuscated execution chain used by LausivLoader.
YARA-L

