Shellcode Injected into attrib.exe via C2-Directed Loader Task
Detects the creation of a remote thread targeting the native Windows utility 'attrib.exe'. This behavior is characteristic of code injection techniques, such as those used by the Sauron loader, where malicious shellcode is executed within the context of a legitimate system process to evade detection and maintain persistence.
Sigma

