Lightlife RAT Chrome Login Data Theft and Wallet Extension Check
This rule detects suspicious PowerShell activity associated with the Lightlife RAT, specifically targeting Google Chrome's login data files to steal credentials and performing checks for the presence of cryptocurrency wallets.
Sigma

