Most Significant TTP 2026: AI-Tool Impersonation SEO-Poisoned Download Deliverin

Detects a suspected ClickFix-style delivery mechanism where a user visits suspicious domains mimicking legitimate CLI tools (e.g., Gemini, Claude) via web browsers. The detection correlates this initial network access with subsequent suspicious Windows RunMRU activity and the spawning of shell processes (powershell.exe, cmd.exe) from explorer.exe using encoded or download-oriented command line arguments within a 5-minute window.