Phishing Series 2026: CastleLoader Portable Python Runtime Execution via ClickFix Chain
Detects the execution of Python interpreters from user-writable directories (Temp, Downloads, AppData) when launched by common LOLBins or shell-like parents, which is indicative of the CastleLoader 'ClickFix' phishing chain where attackers deploy a portable Python runtime to execute malicious payloads.
Sigma

