Kimsuky (Emerald Sleet / APT43) - Malicious CHM File Execution for Initial Acces
Detects the Microsoft HTML Help executable (hh.exe) spawning suspicious child processes such as command interpreters (cmd.exe, powershell.exe) or scripting engines (mshta.exe, wscript.exe). This behavior is characteristic of initial access techniques used by the Kimsuky (APT43) threat group, where malicious CHM files are delivered via email attachments to execute payloads.
Sigma

