It copies itself to the %AppData% or %Temp% folders and creates a Registry key or Scheduled Task to run every time the PC starts.

The RAR is often password-protected (e.g., 1234 or star ) to prevent antivirus software from "peeking" inside the archive during transit.

using a reputable tool like Malwarebytes or Windows Defender.

It scans browsers (Chrome, Edge, Firefox) for saved passwords, credit card info, and cookies .