Sauron Loader screenshot capture chunked exfil over C2 channel
Detects activity associated with the Sauron Loader malware, specifically monitoring for the execution of rnpkeys.exe or loading of tdwp.dll, followed by a high volume of HTTPS POST requests to the same destination host, which is characteristic of chunked screenshot exfiltration.
YARA-L

